Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-16435

Опубликовано: 04 сент. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 5.5

Описание

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

РелизСтатусПримечание
bionic

released

69.0.3497.81-0ubuntu0.18.04.1
cosmic

released

69.0.3497.81-0ubuntu1
devel

released

69.0.3497.81-0ubuntu1
disco

released

69.0.3497.81-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [no longer updated]]
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [no longer updated]
upstream

released

69.0.3497.81-1
xenial

released

69.0.3497.81-0ubuntu0.16.04.1

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needs-triage]
precise/esm

not-affected

1.19.dfsg-1ubuntu3.1
trusty

ignored

end of standard support
trusty/esm

DNE

trusty was needs-triage
upstream

needs-triage

xenial

DNE

Показывать по

РелизСтатусПримечание
bionic

released

2.9-1ubuntu0.1
cosmic

released

2.9-3
devel

released

2.9-3
disco

released

2.9-3
esm-infra-legacy/trusty

released

2.5-0ubuntu4.2
esm-infra/bionic

released

2.9-1ubuntu0.1
esm-infra/xenial

released

2.6-3ubuntu2.1
precise/esm

not-affected

2.2+git20110628-2ubuntu3.3
trusty

released

2.5-0ubuntu4.2
trusty/esm

released

2.5-0ubuntu4.2

Показывать по

РелизСтатусПримечание
bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was ignored [Ubuntu touch end-of-life]]
esm-infra/xenial

ignored

Ubuntu touch end-of-life
precise/esm

DNE

trusty

ignored

end of standard support
trusty/esm

DNE

trusty was ignored [Ubuntu touch end-of-life]
upstream

needs-triage

Показывать по

EPSS

Процентиль: 63%
0.0045
Низкий

4.3 Medium

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
больше 7 лет назад

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

CVSS3: 5.5
nvd
больше 7 лет назад

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

CVSS3: 5.5
debian
больше 7 лет назад

Little CMS (aka Little Color Management System) 2.9 has an integer ove ...

suse-cvrf
больше 7 лет назад

Security update for lcms2

suse-cvrf
больше 7 лет назад

Security update for lcms2

EPSS

Процентиль: 63%
0.0045
Низкий

4.3 Medium

CVSS2

5.5 Medium

CVSS3

Уязвимость CVE-2018-16435