CVE-2016-1645
published 2016-03-13CVE-2016-1645: Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87…
PriorityP339high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.98%
78.3th percentile
Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | <= 49.0.2623.75 | — | |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gp2j-hgg9-c57v: Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k
ghsa_unreviewed·2022-05-13
CVE-2016-1645 [HIGH] CWE-119 GHSA-gp2j-hgg9-c57v: Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k
Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data.
OSV
CVE-2016-1645: Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k
osv·2016-03-13·CVSS 8.8
CVE-2016-1645 [HIGH] CVE-2016-1645: Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k
Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data.
Red Hat
chromium-browser: out-of-bounds write in PDFium
vendor_redhat·2016-03-08·CVSS 8.8
CVE-2016-1645 [HIGH] CWE-787 chromium-browser: out-of-bounds write in PDFium
chromium-browser: out-of-bounds write in PDFium
Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_8.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00073.htmlhttp://www.debian.org/security/2016/dsa-3513http://www.securityfocus.com/bid/84224http://www.securitytracker.com/id/1035259http://www.zerodayinitiative.com/advisories/ZDI-16-197/https://code.google.com/p/chromium/issues/detail?id=587227https://pdfium.googlesource.com/pdfium/+/c145aeb2bf13ac408fc3e8233acca43d4251bbdchttp://googlechromereleases.blogspot.com/2016/03/stable-channel-update_8.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00066.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00067.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-03/msg00073.htmlhttp://www.debian.org/security/2016/dsa-3513http://www.securityfocus.com/bid/84224http://www.securitytracker.com/id/1035259http://www.zerodayinitiative.com/advisories/ZDI-16-197/https://code.google.com/p/chromium/issues/detail?id=587227https://pdfium.googlesource.com/pdfium/+/c145aeb2bf13ac408fc3e8233acca43d4251bbdc
2016-03-13
Published