First published: Sun Aug 07 2016(Updated: )
Heap-based buffer overflow in the opj_j2k_read_SQcd_SQcc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JPEG 2000 data.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Chrome | <=52.0.2743.82 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5140 has a high severity level due to its potential for causing denial of service and unspecified impacts.
To fix CVE-2016-5140, it is recommended to update Google Chrome to version 52.0.2743.116 or later.
CVE-2016-5140 can be exploited by remote attackers using crafted JPEG 2000 data.
CVE-2016-5140 is found in OpenJPEG, which is utilized by PDFium in Google Chrome.
CVE-2016-5140 is classified as a heap-based buffer overflow vulnerability.