Vulnerability Name:

CVE-2016-5139 (CCN-115759)

Assigned:2016-08-03
Published:2016-08-03
Updated:2018-07-21
Summary:Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.
CVSS v3 Severity:7.6 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H)
6.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): High
6.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
5.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
8.8 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-119
CWE-190
CWE-122
CWE-122
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2016-5139

Source: CCN
Type: Google Chrome Releases Web site
Stable Channel Update for Desktop

Source: CONFIRM
Type: Release Notes
http://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop.html

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2016:1982

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2016:1983

Source: CCN
Type: RHSA-2016-1580
Important: chromium-browser security update

Source: REDHAT
Type: UNKNOWN
RHSA-2016:1580

Source: CCN
Type: RHSA-2017-0559
Moderate: openjpeg security update

Source: REDHAT
Type: UNKNOWN
RHSA-2017:0559

Source: CCN
Type: RHSA-2017-0838
Moderate: openjpeg security update

Source: REDHAT
Type: UNKNOWN
RHSA-2017:0838

Source: DEBIAN
Type: UNKNOWN
DSA-3645

Source: CCN
Type: IBM Security Bulletin T1025261 (PowerKVM)
Vulnerabilities in openjpeg affect PowerKVM

Source: BID
Type: UNKNOWN
92276

Source: CCN
Type: BID-92276
Google Chrome Prior to 52.0.2743.116 Multiple Security Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1036547

Source: CONFIRM
Type: UNKNOWN
https://codereview.chromium.org/2124073003

Source: CONFIRM
Type: Permissions Required
https://crbug.com/625541

Source: XF
Type: UNKNOWN
google-chrome-cve20165139-bo(115759)

Source: MLIST
Type: UNKNOWN
[debian-lts-announce] 20180719 [SECURITY] [DLA 1433-1] openjpeg2 security update

Source: FEDORA
Type: UNKNOWN
FEDORA-2016-e9798eaaa3

Source: GENTOO
Type: UNKNOWN
GLSA-201610-09

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2016-5139

Vulnerable Configuration:Configuration 1:
  • cpe:/a:google:chrome:52.0.2743.82:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:6::computenode:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*

  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*

  • Configuration RedHat 9:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*

  • Configuration RedHat 10:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:redhat:enterprise_linux_server_supplementary:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation_supplementary:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop_supplementary:6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:powerkvm:3.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_hpc_node:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_hpc_node:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server_tus:7.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20165139
    V
    CVE-2016-5139
    2023-06-22
    oval:org.opensuse.security:def:7629
    P
    libopenjp2-7-2.3.0-150000.3.8.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:764
    P
    Security update for the Linux Kernel (Important)
    2022-09-16
    oval:org.opensuse.security:def:3044
    P
    cups-filters-1.0.58-19.5.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94674
    P
    libopenjp2-7-2.3.0-150000.3.5.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:170
    P
    libopenssl-1_1-devel-1.1.1d-11.20.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:169
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:93820
    P
    (Important)
    2022-06-10
    oval:org.opensuse.security:def:459
    P
    Security update for libslirp (Important)
    2022-04-29
    oval:org.opensuse.security:def:112065
    P
    chromedriver-55.0.2883.75-3.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:112737
    P
    libopenjp2-7-2.4.0-1.4 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:69751
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:105614
    P
    chromedriver-55.0.2883.75-3.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:106209
    P
    libopenjp2-7-2.4.0-1.4 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:103358
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:89703
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:71289
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61548
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96668
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:46981
    P
    krb5-appl-clients-1.0.3-1.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48137
    P
    libkde4-32bit-4.12.0-10.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47752
    P
    libopenjp2-7-2.1.0-4.9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47681
    P
    libXpm4-3.5.11-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47152
    P
    shim-0.9-20.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48106
    P
    libecpg6-10.10-1.15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47533
    P
    xinetd-2.3.15-7.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47020
    P
    libgc1-7.2d-3.75 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48041
    P
    hardlink-1.0-6.38 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47441
    P
    logwatch-7.4.3-15.65 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46980
    P
    krb5-1.12.5-39.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47690
    P
    libXxf86vm1-1.1.3-3.53 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47309
    P
    libQt5WebKit5-5.6.2-1.31 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47919
    P
    xalan-j2-2.7.0-264.133 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47606
    P
    expat-2.1.0-21.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47116
    P
    pam-1.1.8-14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47848
    P
    perl-Archive-Zip-1.34-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47979
    P
    crash-7.2.1-6.42 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47392
    P
    libplist3-1.12-19.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46995
    P
    libXinerama1-1.1.3-3.54 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48208
    P
    libtirpc-netconfig-1.0.1-17.13.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47817
    P
    libyaml-0-2-0.1.6-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47895
    P
    sudo-1.8.20p2-3.7.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47244
    P
    dracut-044-113.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:100945
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1098
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71928
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62187
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71000
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48611
    P
    qemu-2.6.1-27.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70946
    P
    libXdmcp-devel-1.1.2-1.23 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61259
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46691
    P
    krb5-appl-clients-1.0.3-1.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71059
    P
    opensc-0.17.0-1.30 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48557
    P
    libtasn1-3.7-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48900
    P
    finch-2.12.0-3.3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46827
    P
    python-imaging-1.1.7-21.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48846
    P
    lcms-1.19-17.31 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46706
    P
    libXrandr2-1.4.2-3.56 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46692
    P
    libFLAC++6-1.3.0-6.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:69856
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:64272
    P
    Security update for the Linux Kernel (Important)
    2020-12-09
    oval:org.opensuse.security:def:100533
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107199
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116757
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71594
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61853
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:24963
    P
    Security update for dnsmasq (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25515
    P
    Security update for Mesa (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66500
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:24899
    P
    Security update for webkit2gtk3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25661
    P
    Security update for opensc (Low)
    2020-12-01
    oval:org.opensuse.security:def:24888
    P
    Security update for tcpdump (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25462
    P
    Security update for squid (Important)
    2020-12-01
    oval:org.opensuse.security:def:66408
    P
    grub2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73073
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25617
    P
    Security update for jasper (Low)
    2020-12-01
    oval:org.opensuse.security:def:67706
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25312
    P
    Security update for libsolv (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73191
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25603
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49205
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25228
    P
    Security update for LibreOffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67606
    P
    ghostscript on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26299
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26334
    P
    Security update for Chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25171
    P
    Security update for mailman (Important)
    2020-12-01
    oval:org.opensuse.security:def:49151
    P
    libXt-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64359
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25090
    P
    Security update for git (Important)
    2020-12-01
    oval:com.redhat.rhsa:def:20170838
    P
    RHSA-2017:0838: openjpeg security update (Moderate)
    2017-03-23
    oval:com.redhat.rhsa:def:20170559
    P
    RHSA-2017:0559: openjpeg security update (Moderate)
    2017-03-20
    oval:org.cisecurity:def:1055
    V
    Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116 - CVE-2016-5139
    2016-09-23
    oval:org.cisecurity:def:1005
    P
    DSA-3645-1 -- chromium-browser -- security update
    2016-09-16
    oval:com.ubuntu.disco:def:201651390000000
    V
    CVE-2016-5139 on Ubuntu 19.04 (disco) - medium.
    2016-08-07
    oval:com.ubuntu.xenial:def:20165139000
    V
    CVE-2016-5139 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-08-07
    oval:com.ubuntu.cosmic:def:201651390000000
    V
    CVE-2016-5139 on Ubuntu 18.10 (cosmic) - medium.
    2016-08-07
    oval:com.ubuntu.cosmic:def:20165139000
    V
    CVE-2016-5139 on Ubuntu 18.10 (cosmic) - medium.
    2016-08-07
    oval:com.ubuntu.bionic:def:201651390000000
    V
    CVE-2016-5139 on Ubuntu 18.04 LTS (bionic) - medium.
    2016-08-07
    oval:com.ubuntu.precise:def:20165139000
    V
    CVE-2016-5139 on Ubuntu 12.04 LTS (precise) - medium.
    2016-08-07
    oval:com.ubuntu.artful:def:20165139000
    V
    CVE-2016-5139 on Ubuntu 17.10 (artful) - medium.
    2016-08-07
    oval:com.ubuntu.xenial:def:201651390000000
    V
    CVE-2016-5139 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-08-07
    oval:com.ubuntu.trusty:def:20165139000
    V
    CVE-2016-5139 on Ubuntu 14.04 LTS (trusty) - medium.
    2016-08-07
    oval:com.ubuntu.bionic:def:20165139000
    V
    CVE-2016-5139 on Ubuntu 18.04 LTS (bionic) - medium.
    2016-08-07
    BACK
    google chrome 52.0.2743.82
    redhat enterprise linux server supplementary 6
    redhat enterprise linux workstation supplementary 6
    redhat enterprise linux desktop supplementary 6
    ibm powerkvm 3.1
    redhat enterprise linux desktop 7
    redhat enterprise linux hpc node 7
    redhat enterprise linux server 7
    redhat enterprise linux workstation 7
    redhat enterprise linux desktop 6
    redhat enterprise linux hpc node 6
    redhat enterprise linux server 6
    redhat enterprise linux workstation 6
    redhat enterprise linux server tus 7.3