CVE-2015-1239: Debian Linux

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

Double free vulnerability in the j2k_read_ppm_v3 function in OpenJPEG before r2997, as used in PDFium in Google Chrome, allows remote attackers to cause a denial of service (process crash) via a crafted PDF.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Google Chrome: affected versions not specified
  • Uclouvain Openjpeg: before 2.1.1 (fixed in 2.1.1)

Published 2017-10-18. Last modified 2026-10-08.