pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, does not validate a certain precision value, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted JPEG 2000 image in a PDF document, related to the opj_pi_next_rpcl, opj_pi_next_pcrl, and opj_pi_next_cprl functions.
CVSS Details
- CVSS 3.1 Base Score: 6.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-openjpeg2 | Feb 22, 2016 | Feb 21, 2016 | |
| Gentoo Linux | gentoo-linux-upgrade-media-libs-openjpeggentoo-linux-upgrade-www-client-chromium | Oct 30, 2017 | Feb 21, 2016 | |
| Google Chrome | google-chrome-upgrade-latest | Feb 29, 2016 | Feb 21, 2016 | |
| Ubuntu | ubuntu-upgrade-chromium-browser | Nov 19, 2024 | Feb 21, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub