CVE-2015-6581
Publication date 3 September 2015
Last updated 24 July 2024
Ubuntu priority
Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome before 45.0.2454.85, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering a memory-allocation failure.
Status
Package | Ubuntu Release | Status |
---|---|---|
chromium-browser | 18.04 LTS bionic |
Fixed 45.0.2454.85-0ubuntu1.1198
|
16.04 LTS xenial |
Fixed 45.0.2454.85-0ubuntu1.1198
|
|
14.04 LTS trusty |
Fixed 45.0.2454.85-0ubuntu0.14.04.1.1097
|
|
openjpeg | 18.04 LTS bionic | Not in release |
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
oxide-qt | 18.04 LTS bionic | Not in release |
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
Patch details
Package | Patch details |
---|---|
openjpeg |
|