CVE-2015-1279: Buffer Overflow
Integer overflow in the CJBig2Image::expand function in fxcodec/jbig2/JBig2Image.cpp in PDFium, as used in Google Chrome before 44.0.2403.89, allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via large height and stride values.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-1279?
CVE-2015-1279 has a severity rating that indicates it can lead to denial of service attacks due to a heap-based buffer overflow.
How do I fix CVE-2015-1279?
To fix CVE-2015-1279, users should update to the latest version of Google Chrome or apply patches provided by their Linux distribution.
Which versions of software are affected by CVE-2015-1279?
CVE-2015-1279 affects Google Chrome versions prior to 44.0.2403.89 and various Red Hat and openSUSE Linux versions.
What kind of attack can be executed using CVE-2015-1279?
CVE-2015-1279 can allow remote attackers to execute a denial of service attack that results in a heap-based buffer overflow.
Is there any user action needed to resolve CVE-2015-1279?
Yes, users need to ensure they have upgraded their software to versions that are not vulnerable to CVE-2015-1279.