CVE-2016-1681
published 2016-06-05CVE-2016-1681: Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote…
PriorityP336high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.53%
72.0th percentile
Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| chrome | <= 50.0.2661.102 | — | |
| opensuse | leap | — | — |
| opensuse | opensuse | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
| suse | linux_enterprise | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: heap overflow in pdfium
vendor_redhat·2016-05-25·CVSS 8.8
CVE-2016-1681 [HIGH] chromium-browser: heap overflow in pdfium
chromium-browser: heap overflow in pdfium
Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
GHSA
GHSA-4g7v-x2gv-v9qf: Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k
ghsa_unreviewed·2022-05-14
CVE-2016-1681 [HIGH] CWE-119 GHSA-4g7v-x2gv-v9qf: Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k
Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
OSV
CVE-2016-1681: Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k
osv·2016-06-05·CVSS 8.8
CVE-2016-1681 [HIGH] CVE-2016-1681: Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k
Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
No detection rules found.
No public exploits indexed.
http://googlechromereleases.blogspot.com/2016/05/stable-channel-update_25.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00062.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00063.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.htmlhttp://www.debian.org/security/2016/dsa-3590http://www.securityfocus.com/bid/90876http://www.securitytracker.com/id/1035981https://access.redhat.com/errata/RHSA-2016:1190https://codereview.chromium.org/2001663002https://crbug.com/613160https://security.gentoo.org/glsa/201607-07http://googlechromereleases.blogspot.com/2016/05/stable-channel-update_25.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00062.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-05/msg00063.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00005.htmlhttp://www.debian.org/security/2016/dsa-3590http://www.securityfocus.com/bid/90876http://www.securitytracker.com/id/1035981https://access.redhat.com/errata/RHSA-2016:1190https://codereview.chromium.org/2001663002https://crbug.com/613160https://security.gentoo.org/glsa/201607-07
2016-06-05
Published