7.5
CVSSv2

CVE-2015-6581

Published: 03/09/2015 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Double free vulnerability in the opj_j2k_copy_default_tcp_and_create_tcd function in j2k.c in OpenJPEG before r3002, as used in PDFium in Google Chrome prior to 45.0.2454.85, allows remote malicious users to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering a memory-allocation failure.

Vulnerable Product Search on Vulmon Subscribe to Product

google chrome

Vendor Advisories

Debian Bug report logs - #800453 CVE-2015-6581: Double free vulnerability in opj_j2k_copy_default_tcp_and_create_tcd Package: openjpeg2; Maintainer for openjpeg2 is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Raphael Hertzog <hertzog@debianorg> Date: Tue, 29 Sep 2015 16: ...