« Volver al listado

CVE-2016-1645

Estado: ModificadaAlta (8.8)—

Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2016-1645",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "chrome-cve-admin@google.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2016-03-13T22:59:05.060",
  "references": [
    {
      "url": "http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_8.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00066.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00067.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00073.html",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.debian.org/security/2016/dsa-3513",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/84224",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1035259",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-16-197/",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://code.google.com/p/chromium/issues/detail?id=587227",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "https://pdfium.googlesource.com/pdfium/+/c145aeb2bf13ac408fc3e8233acca43d4251bbdc",
      "source": "chrome-cve-admin@google.com"
    },
    {
      "url": "http://googlechromereleases.blogspot.com/2016/03/stable-channel-update_8.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00066.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00067.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00073.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2016/dsa-3513",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/84224",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1035259",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.zerodayinitiative.com/advisories/ZDI-16-197/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://code.google.com/p/chromium/issues/detail?id=587227",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://pdfium.googlesource.com/pdfium/+/c145aeb2bf13ac408fc3e8233acca43d4251bbdc",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data."
    },
    {
      "lang": "es",
      "value": "Múltiples errores de entero sin signo en la función opj_j2k_update_image_data en j2k.c en OpenJPEG, como se utiliza en PDFium en Google Chrome en versiones anteriores a 49.0.2623.87, permiten a atacantes remotos causar una denegación de servicio (proyección incorrecta y escritura fuera de rango) o posiblemente tener otro impacto no especificado a través de datos JPEG 2000 manipulados."
    }
  ],
  "lastModified": "2026-06-17T00:42:19.810",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "92FD6451-C3E0-450D-A6C2-20304D5C8F39",
              "versionEndIncluding": "49.0.2623.75"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C11E6FB0-C8C0-4527-9AA0-CB9B316F8F43"
            },
            {
              "criteria": "cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4863BE36-D16A-4D75-90D9-FD76DB5B48B7"
            },
            {
              "criteria": "cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A10BC294-9196-425F-9FB0-B1625465B47F"
            },
            {
              "criteria": "cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "03117DF1-3BEC-4B8D-AD63-DBBDB2126081"
            },
            {
              "criteria": "cpe:2.3:o:opensuse:suse_linux_enterprise_server:12.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC3D1104-C0AA-45DE-86A1-5D7CC8281B39"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "chrome-cve-admin@google.com"
}