4.3
CVSSv2

CVE-2013-4276

Published: 28/09/2013 Updated: 21/09/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and previous versions allow remote malicious users to cause a denial of service (crash) via a crafted (1) ICC color profile to the icctrans utility or (2) TIFF image to the tiffdiff utility.

Vulnerable Product Search on Vulmon Subscribe to Product

littlecms little cms color engine 1.17

littlecms little cms color engine 1.11

littlecms little cms color engine 1.12

littlecms little cms color engine 1.09

littlecms little cms color engine 1.10

littlecms little cms color engine 1.07

littlecms little cms color engine 1.08

littlecms little cms color engine 1.15

littlecms little cms color engine 1.16

littlecms little cms color engine 1.18

littlecms little cms color engine

littlecms little cms color engine 1.13

littlecms little cms color engine 1.14

Vendor Advisories

Debian Bug report logs - #718682 liblcms1: CVE-2013-4276: Buffer overflows in Little CMS v119 Package: liblcms1; Maintainer for liblcms1 is (unknown); Reported by: Pedro R <pedrib@gmailcom> Date: Sun, 4 Aug 2013 09:39:02 UTC Severity: grave Tags: patch, security, upstream Found in version 119 Fixed in version lcms/11 ...
Several security issues were fixed in Little CMS ...
Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 119 and earlier allow remote attackers to cause a denial of service (crash) via a crafted (1) ICC color profile to the icctrans utility or (2) TIFF image to the tiffdiff utility ...