Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16435

Опубликовано: 13 авг. 2018
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

Отчет

This issue affects the versions of lcms2 as shipped with Red Hat Enterprise Linux 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5java-1.7.0-openjdkNot affected
Red Hat Enterprise Linux 6java-1.7.0-openjdkNot affected
Red Hat Enterprise Linux 6java-1.8.0-openjdkNot affected
Red Hat Enterprise Linux 6libreofficeNot affected
Red Hat Enterprise Linux 7java-1.7.0-openjdkNot affected
Red Hat Enterprise Linux 7java-1.8.0-openjdkNot affected
Red Hat Enterprise Linux 7lcms2Will not fix
Red Hat Enterprise Linux 8lcms2Will not fix
Red Hat Enterprise Linux 6 Supplementarychromium-browserFixedRHSA-2018:300424.10.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1628969lcms2: Integer overflow in AllocateDataSet() in cmscgats.c leading to heap-based buffer overflow

EPSS

Процентиль: 76%
0.01746
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 8 лет назад

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

CVSS3: 5.5
nvd
почти 8 лет назад

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

CVSS3: 5.5
debian
почти 8 лет назад

Little CMS (aka Little Color Management System) 2.9 has an integer ove ...

suse-cvrf
почти 8 лет назад

Security update for lcms2

suse-cvrf
почти 8 лет назад

Security update for lcms2

EPSS

Процентиль: 76%
0.01746
Низкий

5.5 Medium

CVSS3