Lucene search

K
ubuntucveUbuntu.comUB:CVE-2015-1273
HistoryJul 23, 2015 - 12:00 a.m.

CVE-2015-1273

2015-07-2300:00:00
ubuntu.com
ubuntu.com
14

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.019 Low

EPSS

Percentile

88.7%

Heap-based buffer overflow in j2k.c in OpenJPEG before r3002, as used in
PDFium in Google Chrome before 44.0.2403.89, allows remote attackers to
cause a denial of service or possibly have unspecified other impact via
invalid JPEG2000 data in a PDF document.

Bugs

Notes

Author Note
tyhicks There are large changes between openjpeg trunk and the 1.5 and 1.3 branches that we shipped in Vivid and older. However, it looks like those code bases are also affected because I don’t see similar sanity checks. As of 2015-07-24, I don’t see a fix in the 1.5 branch.
OSVersionArchitecturePackageVersionFilename
ubuntu17.10noarchchromium-browser< 44.0.2403.89-0ubuntu1.1195UNKNOWN
ubuntu18.04noarchchromium-browser< 44.0.2403.89-0ubuntu1.1195UNKNOWN
ubuntu18.10noarchchromium-browser< 44.0.2403.89-0ubuntu1.1195UNKNOWN
ubuntu19.04noarchchromium-browser< 44.0.2403.89-0ubuntu1.1195UNKNOWN
ubuntu19.10noarchchromium-browser< 44.0.2403.89-0ubuntu1.1195UNKNOWN
ubuntu20.04noarchchromium-browser< 44.0.2403.89-0ubuntu1.1195UNKNOWN
ubuntu20.10noarchchromium-browser< 44.0.2403.89-0ubuntu1.1195UNKNOWN
ubuntu21.04noarchchromium-browser< 44.0.2403.89-0ubuntu1.1195UNKNOWN
ubuntu21.10noarchchromium-browser< 44.0.2403.89-0ubuntu1.1195UNKNOWN
ubuntu22.04noarchchromium-browser< 44.0.2403.89-0ubuntu1.1195UNKNOWN
Rows per page:
1-10 of 221

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.019 Low

EPSS

Percentile

88.7%