CVE Vulnerabilities

CVE-2015-1239

Double Free

Published: Oct 18, 2017 | Modified: Dec 29, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Openjpeg Uclouvain * 2.1.1 (excluding)
Openjpeg Ubuntu upstream *
Openjpeg2 Ubuntu upstream *
Openjpeg2 Ubuntu xenial *

Potential Mitigations

References