CVE-2016-5158: Buffer Overflow
Multiple integer overflows in the opjtcdinittile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-5158?
CVE-2016-5158 has a moderate severity level as it allows remote attackers to cause a denial of service due to heap-based buffer overflow.
How do I fix CVE-2016-5158?
To mitigate CVE-2016-5158, update Google Chrome to version 53.0.2785.89 or later, or upgrade your affected OpenSUSE version beyond 42.1.
Which software is affected by CVE-2016-5158?
CVE-2016-5158 affects Google Chrome versions up to 52.0.2743.116 and OpenSUSE Leap 42.1.
Can CVE-2016-5158 lead to data loss?
While CVE-2016-5158 primarily causes denial of service, it may potentially lead to data loss if the application crashes during critical operations.
Is CVE-2016-5158 exploitative in nature?
Yes, attackers can exploit CVE-2016-5158 to crash the application or potentially execute arbitrary code, thus posing a security risk.