Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-7455

Опубликовано: 07 мая 2016
Источник: debian
EPSS Средний

Описание

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lcms2fixed2.6-1package
lcms2not-affectedwheezypackage

Примечания

  • https://www.kb.cert.org/vuls/id/369800

  • https://github.com/mm2/Little-CMS/commit/fefaaa43c382eee632ea3ad0cfa915335140e1db#diff-189a94f0a7a47efdd43f5567e27a973b

EPSS

Процентиль: 94%
0.15231
Средний

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 10 лет назад

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.

redhat
почти 10 лет назад

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.

CVSS3: 9.8
nvd
почти 10 лет назад

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.

CVSS3: 9.8
github
больше 3 лет назад

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.

EPSS

Процентиль: 94%
0.15231
Средний