Vulnerability Name:

CVE-2016-5159 (CCN-116534)

Assigned:2016-08-31
Published:2016-08-31
Updated:2018-10-30
Summary:Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data that is mishandled during opj_aligned_malloc calls in dwt.c and t1.c.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
6.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L)
5.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
8.8 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (REDHAT CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-190
CWE-190
CWE-122
CWE-122
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2016-5159

Source: CCN
Type: Google Chrome Releases Web site
Stable Channel Update for Desktop

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2016:2250

Source: SUSE
Type: UNKNOWN
SUSE-SU-2016:2251

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2016:2296

Source: SUSE
Type: Third Party Advisory
openSUSE-SU-2016:2349

Source: CCN
Type: RHSA-2016-1854
Important: chromium-browser security update

Source: REDHAT
Type: UNKNOWN
RHSA-2016:1854

Source: CCN
Type: RHSA-2017-0559
Moderate: openjpeg security update

Source: REDHAT
Type: UNKNOWN
RHSA-2017:0559

Source: CCN
Type: RHSA-2017-0838
Moderate: openjpeg security update

Source: REDHAT
Type: UNKNOWN
RHSA-2017:0838

Source: DEBIAN
Type: UNKNOWN
DSA-3660

Source: DEBIAN
Type: UNKNOWN
DSA-3768

Source: CCN
Type: IBM Security Bulletin T1025261 (PowerKVM)
Vulnerabilities in openjpeg affect PowerKVM

Source: BID
Type: UNKNOWN
92717

Source: CCN
Type: BID-92717
Google Chrome Prior to 53.0.2785.89 Multiple Security Vulnerabilities

Source: SECTRACK
Type: UNKNOWN
1036729

Source: CONFIRM
Type: Issue Tracking
https://codereview.chromium.org/2218783002/

Source: CONFIRM
Type: Permissions Required
https://crbug.com/628304

Source: XF
Type: UNKNOWN
google-chrome-cve20165159-bo(116534)

Source: CONFIRM
Type: Vendor Advisory
https://googlechromereleases.blogspot.com/2016/08/stable-channel-update-for-desktop_31.html

Source: GENTOO
Type: UNKNOWN
GLSA-201610-09

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2016-5159

Vulnerable Configuration:Configuration 1:
  • cpe:/o:opensuse:leap:42.1:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:google:chrome:*:*:*:*:*:*:*:* (Version <= 52.0.2743.116)

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:6:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:6::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:6::computenode:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:6::server:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:6::workstation:*:*:*:*:*

  • Configuration RedHat 6:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Configuration RedHat 7:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*

  • Configuration RedHat 8:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*

  • Configuration RedHat 9:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*

  • Configuration RedHat 10:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:redhat:enterprise_linux_server_supplementary:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation_supplementary:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop_supplementary:6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:powerkvm:3.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_hpc_node:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_hpc_node:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:6:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server_tus:7.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20165159
    V
    CVE-2016-5159
    2023-06-22
    oval:org.opensuse.security:def:7629
    P
    libopenjp2-7-2.3.0-150000.3.8.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:764
    P
    Security update for the Linux Kernel (Important)
    2022-09-16
    oval:org.opensuse.security:def:3044
    P
    cups-filters-1.0.58-19.5.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94674
    P
    libopenjp2-7-2.3.0-150000.3.5.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:169
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:170
    P
    libopenssl-1_1-devel-1.1.1d-11.20.1 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:93820
    P
    (Important)
    2022-06-10
    oval:org.opensuse.security:def:459
    P
    Security update for libslirp (Important)
    2022-04-29
    oval:org.opensuse.security:def:112065
    P
    chromedriver-55.0.2883.75-3.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:69751
    P
    Security update for binutils (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:105614
    P
    chromedriver-55.0.2883.75-3.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:71289
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:61548
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:96668
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:103358
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:89703
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:46981
    P
    krb5-appl-clients-1.0.3-1.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47848
    P
    perl-Archive-Zip-1.34-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47681
    P
    libXpm4-3.5.11-5.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47152
    P
    shim-0.9-20.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48208
    P
    libtirpc-netconfig-1.0.1-17.13.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47817
    P
    libyaml-0-2-0.1.6-7.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47533
    P
    xinetd-2.3.15-7.3 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47020
    P
    libgc1-7.2d-3.75 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48137
    P
    libkde4-32bit-4.12.0-10.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47752
    P
    libopenjp2-7-2.1.0-4.9.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47441
    P
    logwatch-7.4.3-15.65 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46980
    P
    krb5-1.12.5-39.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48106
    P
    libecpg6-10.10-1.15.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47690
    P
    libXxf86vm1-1.1.3-3.53 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47309
    P
    libQt5WebKit5-5.6.2-1.31 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48041
    P
    hardlink-1.0-6.38 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47606
    P
    expat-2.1.0-21.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47116
    P
    pam-1.1.8-14.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47979
    P
    crash-7.2.1-6.42 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47392
    P
    libplist3-1.12-19.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:46995
    P
    libXinerama1-1.1.3-3.54 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47919
    P
    xalan-j2-2.7.0-264.133 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47895
    P
    sudo-1.8.20p2-3.7.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47244
    P
    dracut-044-113.10 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:100945
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1098
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71928
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62187
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:5080
    P
    Security update for dbus-1 (Important)
    2021-07-21
    oval:org.opensuse.security:def:5067
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:5740
    P
    Security update for libjpeg-turbo (Moderate)
    2021-06-11
    oval:org.opensuse.security:def:5058
    P
    Security update for the Linux Kernel (Important)
    2021-06-09
    oval:org.opensuse.security:def:46691
    P
    krb5-appl-clients-1.0.3-1.5 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48611
    P
    qemu-2.6.1-27.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46827
    P
    python-imaging-1.1.7-21.15 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:70946
    P
    libXdmcp-devel-1.1.2-1.23 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71059
    P
    opensc-0.17.0-1.30 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48557
    P
    libtasn1-3.7-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46706
    P
    libXrandr2-1.4.2-3.56 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48900
    P
    finch-2.12.0-3.3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46692
    P
    libFLAC++6-1.3.0-6.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:71000
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48846
    P
    lcms-1.19-17.31 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:61259
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:69856
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:5718
    P
    Security update for avahi (Important)
    2021-06-03
    oval:org.opensuse.security:def:5049
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:5016
    P
    Security update for the Linux Kernel (Important)
    2021-04-15
    oval:org.opensuse.security:def:64272
    P
    Security update for the Linux Kernel (Important)
    2020-12-09
    oval:org.opensuse.security:def:107199
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116757
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71594
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61853
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:100533
    P
    libopenjp2-7-2.3.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:4789
    P
    Security update for skopeo (Important)
    2020-12-02
    oval:org.opensuse.security:def:4767
    P
    Security update for freeradius-server (Important)
    2020-12-02
    oval:org.opensuse.security:def:4759
    P
    Security update for salt (Important)
    2020-12-02
    oval:org.opensuse.security:def:4991
    P
    Security update for nodejs10 (Important)
    2020-12-02
    oval:org.opensuse.security:def:4916
    P
    Security update for mariadb (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4897
    P
    Security update for dpdk (Critical)
    2020-12-02
    oval:org.opensuse.security:def:4882
    P
    Security update for mozilla-nss (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:4835
    P
    Security update for MozillaFirefox (Important)
    2020-12-02
    oval:org.opensuse.security:def:49151
    P
    libXt-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64359
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66500
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66408
    P
    grub2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73073
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67706
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73191
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49205
    P
    libopenjp2-7 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:67606
    P
    ghostscript on GA media (Moderate)
    2020-12-01
    oval:com.redhat.rhsa:def:20170838
    P
    RHSA-2017:0838: openjpeg security update (Moderate)
    2017-03-23
    oval:com.redhat.rhsa:def:20170559
    P
    RHSA-2017:0559: openjpeg security update (Moderate)
    2017-03-20
    oval:org.cisecurity:def:1146
    V
    Multiple integer overflows in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows - CVE-2016-5159
    2016-10-14
    oval:org.cisecurity:def:1155
    P
    DSA-3660-1 -- chromium-browser -- security update
    2016-10-14
    oval:com.ubuntu.disco:def:201651590000000
    V
    CVE-2016-5159 on Ubuntu 19.04 (disco) - medium.
    2016-09-11
    oval:com.ubuntu.xenial:def:20165159000
    V
    CVE-2016-5159 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-09-11
    oval:com.ubuntu.cosmic:def:201651590000000
    V
    CVE-2016-5159 on Ubuntu 18.10 (cosmic) - medium.
    2016-09-11
    oval:com.ubuntu.cosmic:def:20165159000
    V
    CVE-2016-5159 on Ubuntu 18.10 (cosmic) - medium.
    2016-09-11
    oval:com.ubuntu.bionic:def:201651590000000
    V
    CVE-2016-5159 on Ubuntu 18.04 LTS (bionic) - medium.
    2016-09-11
    oval:com.ubuntu.precise:def:20165159000
    V
    CVE-2016-5159 on Ubuntu 12.04 LTS (precise) - medium.
    2016-09-11
    oval:com.ubuntu.artful:def:20165159000
    V
    CVE-2016-5159 on Ubuntu 17.10 (artful) - medium.
    2016-09-11
    oval:com.ubuntu.xenial:def:201651590000000
    V
    CVE-2016-5159 on Ubuntu 16.04 LTS (xenial) - medium.
    2016-09-11
    oval:com.ubuntu.trusty:def:20165159000
    V
    CVE-2016-5159 on Ubuntu 14.04 LTS (trusty) - medium.
    2016-09-11
    oval:com.ubuntu.bionic:def:20165159000
    V
    CVE-2016-5159 on Ubuntu 18.04 LTS (bionic) - medium.
    2016-09-11
    BACK
    opensuse leap 42.1
    google chrome *
    redhat enterprise linux server supplementary 6
    redhat enterprise linux workstation supplementary 6
    redhat enterprise linux desktop supplementary 6
    ibm powerkvm 3.1
    redhat enterprise linux desktop 7
    redhat enterprise linux hpc node 7
    redhat enterprise linux server 7
    redhat enterprise linux workstation 7
    redhat enterprise linux desktop 6
    redhat enterprise linux hpc node 6
    redhat enterprise linux server 6
    redhat enterprise linux workstation 6
    redhat enterprise linux server tus 7.3