CVE-2016-5157
published 2016-09-11CVE-2016-5157: Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS…
PriorityP348high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
4.70%
90.8th percentile
Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafted coordinate values in JPEG 2000 data.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openjpeg2 | < openjpeg2 2.1.2-1 (bookworm) | openjpeg2 2.1.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| chrome | <= 52.0.2743.116 | — | |
| opensuse | leap | — | — |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1 | 2.1.2-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1 | 2.1.2-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1 | 2.1.2-1 |
| the_openjpeg_project | openjpeg2 | >= 0 < 2.1.2-1 | 2.1.2-1 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4w78-qc97-hvjf: Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt
ghsa_unreviewed·2022-05-14
CVE-2016-5157 [HIGH] CWE-119 GHSA-4w78-qc97-hvjf: Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt
Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafted coordinate values in JPEG 2000 data.
OSV
CVE-2016-5157: Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt
osv·2016-09-11·CVSS 8.8
CVE-2016-5157 [HIGH] CVE-2016-5157: Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt
Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafted coordinate values in JPEG 2000 data.
Red Hat
chromium-browser: heap overflow in pdfium
vendor_redhat·2016-08-31·CVSS 8.8
CVE-2016-5157 [HIGH] chromium-browser: heap overflow in pdfium
chromium-browser: heap overflow in pdfium
Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafted coordinate values in JPEG 2000 data.
Debian
CVE-2016-5157: openjpeg2 - Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in Open...
vendor_debian·2016·CVSS 8.8
CVE-2016-5157 [HIGH] CVE-2016-5157: openjpeg2 - Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in Open...
Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafted coordinate values in JPEG 2000 data.
Scope: local
bookworm: resolved (fixed in 2.1.2-1)
bullseye: resolved (fixed in 2.1.2-1)
forky: resolved (fixed in 2.1.2-1)
sid: resolved (fixed in 2.1.2-1)
trixie: resolved (fixed in 2.1.2-1)
No detection rules found.
No public exploits indexed.
HackerOne
CVE-2016-5157 OpenJPEG opj_dwt_interleave_v Out-of-Bounds Write Vulnerability
hackerone·2019-11-12·CVSS 8.8
CVE-2016-5157 [HIGH] CVE-2016-5157 OpenJPEG opj_dwt_interleave_v Out-of-Bounds Write Vulnerability
CVE-2016-5157 OpenJPEG opj_dwt_interleave_v Out-of-Bounds Write Vulnerability
# OpenJPEG opj_dwt_interleave_v Out-of-Bounds Write Vulnerability
## 1. About OpenJPEG
OpenJPEG is an open-source JPEG 2000 codec written in C language. It's widely used in lots of Linux OSes such as Ubuntu, RedHat, Debian, Fedora, and so on. The official repository of the OpenJPEG project is available at [GitHub](https://github.com/uclouvain/openjpeg).
## 2. Credit
This vulnerability was discovered by Ke Liu of Tencent's Xuanwu LAB.
## 3. Testing Environments
+ **OS**: Ubuntu
+ **OpenJPEG**: [4a2a869](https://github.com/uclouvain/openjpeg/archive/4a2a8693e5a02207a8813b02a375abdc4e43c49b.zip) (Master version before Aug/6/2016)
+ **Compiler**: Clang
+ **CFLAGS**: ``-g -O0 -fsanitize=address``
## 4. Reproduce
Bugzilla
openjpeg: Heap buffer overflow in opj_dwt_interleave_v in dwt.c
bugzilla·2016-09-08·CVSS 8.8
[HIGH] openjpeg: Heap buffer overflow in opj_dwt_interleave_v in dwt.c
openjpeg: Heap buffer overflow in opj_dwt_interleave_v in dwt.c
An out-of-bounds write was found in function opj_dwt_interleave_v of dwt.c
Upstream patch:
https://github.com/uclouvain/openjpeg/commit/e078172b1c3f98d2219c37076b238fb759c751ea
CVE request:
http://seclists.org/oss-sec/2016/q3/438
Discussion:
Created openjpeg tracking bugs for this issue:
Affects: fedora-all [bug 1374339]
---
Created mingw-openjpeg tracking bugs for this issue:
Affects: fedora-all [bug 1374341]
---
Created openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1374340]
Affects: epel-all [bug 1374343]
---
Created mingw-openjpeg2 tracking bugs for this issue:
Affects: fedora-all [bug 1374342]
---
The same vulnerability was previously fixed in Chromium as CVE-2016-5157 (bug 1372218).
Bugzilla
chromium: various flaws [fedora-all]
bugzilla·2016-09-01·CVSS 6.1
[MEDIUM] chromium: various flaws [fedora-all]
chromium: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
one tracking bug has b
Bugzilla
CVE-2016-5157 chromium-browser: heap overflow in pdfium
bugzilla·2016-09-01·CVSS 8.8
CVE-2016-5157 [HIGH] CVE-2016-5157 chromium-browser: heap overflow in pdfium
CVE-2016-5157 chromium-browser: heap overflow in pdfium
A heap overflow flaw was found in the PDFium component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=632622
External References:
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: fedora-all [bug 1372232]
---
chromium-53.0.2785.101-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2016:1854 https://rhn.redhat.com/errata/RHSA-2016-1854.html
---
chromium-53.0.2785.101-1.fc25 has b
http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-09/msg00008.htmlhttp://lists.opensuse.org/opensuse-updates/2016-09/msg00073.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1854.htmlhttp://www.debian.org/security/2016/dsa-3660http://www.debian.org/security/2017/dsa-4013http://www.openwall.com/lists/oss-security/2016/09/08/5http://www.securityfocus.com/bid/92717http://www.securitytracker.com/id/1036729https://bugzilla.redhat.com/show_bug.cgi?id=1374337https://crbug.com/632622https://github.com/uclouvain/openjpeg/commit/e078172b1c3f98d2219c37076b238fb759c751eahttps://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2T6IQAMS4W65MGP7UW5FPE22PXELTK5D/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/66BWMMMWXH32J5AOGLAJGZA3GH5LZHXH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AQ2IIIQSJ3J4MONBOGCG6XHLKKJX2HKM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4IRSGYMBSHCBZP23CUDIRJ3LBKH6ZJ7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JYLOX7PZS3ZUHQ6RGI3M6H27B7I5ZZ26/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YGKSEWWWED77Q5ZHK4OA2EKSJXLRU3MK/https://pdfium.googlesource.com/pdfium/+/b6befb2ed2485a3805cddea86dc7574510178ea9https://security.gentoo.org/glsa/201610-09http://lists.opensuse.org/opensuse-security-announce/2016-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-09/msg00008.htmlhttp://lists.opensuse.org/opensuse-updates/2016-09/msg00073.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1854.htmlhttp://www.debian.org/security/2016/dsa-3660http://www.debian.org/security/2017/dsa-4013http://www.openwall.com/lists/oss-security/2016/09/08/5http://www.securityfocus.com/bid/92717http://www.securitytracker.com/id/1036729https://bugzilla.redhat.com/show_bug.cgi?id=1374337https://crbug.com/632622https://github.com/uclouvain/openjpeg/commit/e078172b1c3f98d2219c37076b238fb759c751eahttps://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2T6IQAMS4W65MGP7UW5FPE22PXELTK5D/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/66BWMMMWXH32J5AOGLAJGZA3GH5LZHXH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AQ2IIIQSJ3J4MONBOGCG6XHLKKJX2HKM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4IRSGYMBSHCBZP23CUDIRJ3LBKH6ZJ7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JYLOX7PZS3ZUHQ6RGI3M6H27B7I5ZZ26/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YGKSEWWWED77Q5ZHK4OA2EKSJXLRU3MK/https://pdfium.googlesource.com/pdfium/+/b6befb2ed2485a3805cddea86dc7574510178ea9https://security.gentoo.org/glsa/201610-09
2016-09-11
Published