pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, does not validate a certain precision value, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted JPEG 2000 image in a PDF document, related to the opj_pi_next_rpcl, opj_pi_next_pcrl, and opj_pi_next_cprl functions.
CVSS Details
- CVSS 3.1 Base Score: 6.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openjpeg2 | Feb 22, 2016 | Feb 21, 2016 |
| Gentoo Linux | — | Upgrade media-libs/openjpeg.Upgrade www-client/chromium. | Oct 30, 2017 | Feb 21, 2016 |
| Google Chrome | — | Upgrade to the latest version of Google Chrome | Feb 29, 2016 | Feb 9, 2016 |
| Ubuntu | — | Upgrade chromium-browser | Nov 19, 2024 | Feb 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub