Candidate: CVE-2016-1645 PublicDate: 2016-03-13 22:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1645 Description: Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_chromium-browser: upstream_chromium-browser: released (49.0.2623.87) precise_chromium-browser: ignored trusty_chromium-browser: released (49.0.2623.87-0ubuntu0.14.04.1.1112) trusty/esm_chromium-browser: DNE (trusty was released [49.0.2623.87-0ubuntu0.14.04.1.1112]) vivid/ubuntu-core_chromium-browser: DNE vivid/stable-phone-overlay_chromium-browser: DNE wily_chromium-browser: released (49.0.2623.87-0ubuntu0.15.10.1.1222) devel_chromium-browser: released (49.0.2623.87-0ubuntu1.1232) Patches_oxide-qt: upstream_oxide-qt: not-affected precise_oxide-qt: DNE trusty_oxide-qt: not-affected trusty/esm_oxide-qt: DNE (trusty was not-affected) vivid/ubuntu-core_oxide-qt: DNE vivid/stable-phone-overlay_oxide-qt: not-affected wily_oxide-qt: not-affected devel_oxide-qt: not-affected