CVE-2016-5152 is an integer overflow vulnerability in the OpenJPEG library, specifically within the opj_tcd_get_decoded_tile_size function, impacting Google Chrome and OpenSUSE products. This flaw allows remote attackers to trigger a heap-based buffer overflow, leading to a denial of service or potentially other unspecified impacts, through specially crafted JPEG 2000 data. Rated with a CVSS score of 8.8 (High), it requires user interaction (UI:R) but has low attack complexity (AC:L) and can result in high confidentiality, integrity, and availability impacts. While the vulnerability has a high risk score and some community discussion, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 52.0.2743.116CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
42.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.