CVE-2016-1645: Buffer Overflow
Multiple integer signedness errors in the opjj2kupdateimagedata function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1645?
CVE-2016-1645 has been classified with a severity rating that allows remote attackers to cause a denial of service.
How do I fix CVE-2016-1645?
To fix CVE-2016-1645, upgrade Google Chrome to version 49.0.2623.87 or later, or update your affected OpenSUSE or Debian systems.
What systems are affected by CVE-2016-1645?
CVE-2016-1645 affects Google Chrome versions prior to 49.0.2623.87, as well as certain versions of Debian and OpenSUSE.
What type of vulnerabilities does CVE-2016-1645 exploit?
CVE-2016-1645 exploits multiple integer signedness errors, leading to out-of-bounds writes.
Can CVE-2016-1645 be exploited remotely?
Yes, CVE-2016-1645 allows remote attackers to exploit the vulnerability and cause a denial of service.