The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, miscalculates a certain layer index value, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.
| Software | From | Fixed in |
|---|---|---|
| google / chrome | 48.0.2564.103 | 48.0.2564.103.x |
| opensuse / opensuse | 13.1 | 13.1.x |
| debian / debian_linux | 8.0 | 8.0.x |