Candidate: CVE-2015-6776 PublicDate: 2015-12-06 01:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6776 http://googlechromereleases.blogspot.com/2015/12/stable-channel-update.html Description: The opj_dwt_decode_1* functions in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 47.0.2526.73, allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG 2000 data that is mishandled during a discrete wavelet transform. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Hanno Böck Assigned-to: CVSS: Patches_chromium-browser: upstream_chromium-browser: released (47.0.2526.73) precise_chromium-browser: ignored trusty_chromium-browser: released (47.0.2526.73-0ubuntu0.14.04.1.1106) trusty/esm_chromium-browser: DNE (trusty was released [47.0.2526.73-0ubuntu0.14.04.1.1106]) vivid_chromium-browser: released (47.0.2526.73-0ubuntu0.15.04.1.1190) wily_chromium-browser: released (47.0.2526.73-0ubuntu0.15.10.1.1215) devel_chromium-browser: released (47.0.2526.73-0ubuntu1.1218) Patches_oxide-qt: upstream_oxide-qt: not-affected precise_oxide-qt: DNE trusty_oxide-qt: not-affected trusty/esm_oxide-qt: DNE (trusty was not-affected) vivid_oxide-qt: not-affected wily_oxide-qt: not-affected devel_oxide-qt: not-affected