First published: Mon Apr 18 2016(Updated: )
fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc422_to_rgb functions, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via crafted JPEG 2000 data in a PDF document.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <=49.0.2623.112 | |
Debian Linux | =8.0 | |
SUSE Linux | =42.1 | |
SUSE Linux Enterprise Server | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1651 is rated as a medium severity vulnerability due to potential information disclosure and denial of service risks.
To fix CVE-2016-1651, you should update Google Chrome to version 50.0.2661.75 or newer.
CVE-2016-1651 affects Google Chrome versions prior to 50.0.2661.75, as well as certain Debian and SUSE Linux distributions.
Yes, CVE-2016-1651 can be exploited by remote attackers to read sensitive information from process memory.
There are no known workarounds for CVE-2016-1651; the best mitigation is to apply the necessary updates.