CVE-2016-5157

HIGH

Opensuse Leap < 52.0.2743.116 - Memory Corruption

Title source: rule
STIX 2.1

Description

Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafted coordinate values in JPEG 2000 data.

References (22)

Core 22
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/92717
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1036729
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2016/09/08/5
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2017/dsa-4013
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2016-09/msg00073.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2016/dsa-3660
Issue Tracking x_refsource_confirm
https://crbug.com/632622
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201610-09
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2016-1854.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1374337

Scores

CVSS v3 8.8
EPSS 0.0659
EPSS Percentile 91.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (5)
fedoraproject/fedora 23
fedoraproject/fedora 24
fedoraproject/fedora 25
google/chrome < 52.0.2743.116
opensuse/leap 42.1
Published Sep 11, 2016
Tracked Since Feb 18, 2026