Google Chrome opj_dwt_decode_1 * DoS Vulnerability (CVE-2015-6776)
Google Chrome opj_dwt_decode_1 * DoS Vulnerability (CVE-2015-6776)
Release date:
Updated on:
Affected Systems:
Google Chrome <47.0.2526.73
Description:
CVE (CAN) ID: CVE-2015-6776
Google Chrome is a Web browser tool developed by Google.
In PDFium versions earlier than Google Chrome 47.0.2526.73, the dwt in OpenJPEG is used. c's function opj_dwt_decode_1 * has a security vulnerability. Remote attackers construct JPEG 2000 data and process it incorrectly in discrete wavelet transform, which can cause denial of service (out-of-bounds array access ).
<* Source: Google
*>
Suggestion:
Vendor patch:
Google
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://googlechromereleases.blogspot.com/2015/12/stable-channel-update.html
This article permanently updates the link address: