Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10165

Опубликовано: 03 фев. 2017
Источник: debian
EPSS Низкий

Описание

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lcms2fixed2.8-4package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1367357

  • https://github.com/mm2/Little-CMS/commit/5ca71a7bc18b6897ab21d815d15e218e204581e2

EPSS

Процентиль: 66%
0.00513
Низкий

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 9 лет назад

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

CVSS3: 7.1
redhat
больше 9 лет назад

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

CVSS3: 7.1
nvd
около 9 лет назад

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

CVSS3: 7.1
github
больше 3 лет назад

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

suse-cvrf
больше 7 лет назад

Security update for lcms2

EPSS

Процентиль: 66%
0.00513
Низкий