Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-16435

Опубликовано: 04 сент. 2018
Источник: debian

Описание

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lcms2fixed2.9-3package
lcmsremovedpackage
chromium-browserfixed69.0.3497.81-1package
chromium-browserend-of-lifejessiepackage

Примечания

  • https://github.com/mm2/Little-CMS/issues/171

  • https://github.com/mm2/Little-CMS/commit/768f70ca405cd3159d990e962d54456773bb8cf8

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

CVSS3: 5.5
redhat
больше 7 лет назад

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

CVSS3: 5.5
nvd
больше 7 лет назад

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

suse-cvrf
больше 7 лет назад

Security update for lcms2

suse-cvrf
больше 7 лет назад

Security update for lcms2