10
CVSSv2

CVE-2008-5317

Published: 03/12/2008 Updated: 03/10/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) prior to 1.17 allows malicious users to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.

Vulnerable Product Search on Vulmon Subscribe to Product

littlecms lcms 1.08

littlecms lcms 1.07

littlecms little cms color engine 1.14

littlecms little cms color engine 1.07

littlecms little cms color engine 1.15

littlecms lcms 1.12

littlecms lcms 1.11

littlecms little cms color engine 1.11

littlecms little cms color engine 1.10

littlecms lcms

littlecms lcms 1.14

littlecms lcms 1.13

littlecms little cms color engine 1.13

littlecms little cms color engine 1.12

littlecms lcms 1.15

littlecms little cms color engine

littlecms lcms 1.10

littlecms lcms 1.09

littlecms little cms color engine 1.09

littlecms little cms color engine 1.08

Vendor Advisories

Synopsis Moderate: lcms security update Type/Severity Security Advisory: Moderate Topic Updated lcms packages that resolve several security issues are nowavailable for Red Hat Enterprise Linux 5This update has been rated as having moderate security impact by the RedHat Security Response Team Desc ...
Chris Evans discovered that certain ICC operations in lcms were not correctly bounds-checked If a user or automated system were tricked into processing an image with malicious ICC tags, a remote attacker could crash applications linked against liblcms1, leading to a denial of service, or possibly execute arbitrary code with user privileges ...
It was discovered that certain gamma operations in lcms were not correctly bounds-checked If a user or automated system were tricked into processing a malicious image, a remote attacker could crash applications linked against liblcms1, leading to a denial of service, or possibly execute arbitrary code with user privileges ...
Two vulnerabilities have been found in lcms, a library and set of commandline utilities for image color management The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-5316 Inadequate enforcement of fixed-length buffer limits allows an attacker to overflow a buffer on the stack, potentially enabling ...