Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-16435

Опубликовано: 04 сент. 2018
Источник: debian
EPSS Низкий

Описание

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lcms2fixed2.9-3package
lcmsremovedpackage
chromium-browserfixed69.0.3497.81-1package
chromium-browserend-of-lifejessiepackage

Примечания

  • https://github.com/mm2/Little-CMS/issues/171

  • https://github.com/mm2/Little-CMS/commit/768f70ca405cd3159d990e962d54456773bb8cf8

EPSS

Процентиль: 76%
0.01746
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

CVSS3: 5.5
redhat
около 8 лет назад

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

CVSS3: 5.5
nvd
почти 8 лет назад

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

suse-cvrf
почти 8 лет назад

Security update for lcms2

suse-cvrf
почти 8 лет назад

Security update for lcms2

EPSS

Процентиль: 76%
0.01746
Низкий