Описание
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
Ссылки
- ExploitThird Party Advisory
- Patch
- Patch
- Broken Link
- Mailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.18 (включая)
cpe:2.3:a:littlecms:little_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 29%
0.00365
Низкий
4 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-696
CWE-190
Связанные уязвимости
CVSS3: 4
ubuntu
3 месяца назад
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
CVSS3: 6.1
redhat
3 месяца назад
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
CVSS3: 4
debian
3 месяца назад
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in ...
CVSS3: 4
github
3 месяца назад
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
EPSS
Процентиль: 29%
0.00365
Низкий
4 Medium
CVSS3
7.5 High
CVSS3
Дефекты
CWE-696
CWE-190