CVE-2015-1239
Publication date 18 October 2017
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| openjpeg2 | ||
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Fixed 2.1.2-1.1+deb9u2build0.1
|
|
| 14.04 LTS trusty | Not in release | |
| openjpeg | ||
| 22.04 LTS jammy | Not in release | |
| 20.04 LTS focal | Not in release | |
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
Notes
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | None |
| User interaction | Required |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity impact | None |
| Availability impact | High |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
References
Other references
- https://bugs.chromium.org/p/chromium/issues/detail?id=430891
- https://bugs.chromium.org/p/chromium/issues/detail?id=457493
- https://gist.github.com/bittorrent3389/8fee7cdaa73d1d351ee9
- https://github.com/uclouvain/openjpeg/commit/28c6f547987e8cbe5ccaef622da4cf6667068989
- https://www.cve.org/CVERecord?id=CVE-2015-1239