This vulnerability is an instance of a memory corruption vulnerability in JPEG 2000 code-stream tile manipulation. The vulnerability is caused by a crafted PDF file with embedded JPEG 2000 code-stream that contains tile data that causes out of bound access when copying memory blocks representing tile regions. It causes an out of bounds memory access, which sometimes triggers access violation exception. Attackers can exploit the vulnerability by using the out of bounds access for unintended reads, writes or frees potentially leading to code corruption, control-flow hijack, or information leak attack. |