5.5
CVSSv3

CVE-2018-16435

Published: 04/09/2018 Updated: 26/05/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

littlecms little cms color engine 2.9

canonical ubuntu linux 18.04

canonical ubuntu linux 12.04

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

redhat enterprise linux server 6.0

redhat enterprise linux desktop 6.0

redhat enterprise linux workstation 6.0

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Synopsis Important: chromium-browser security update Type/Severity Security Advisory: Important Topic An update for chromium-browser is now available for Red Hat Enterprise Linux 6 SupplementaryRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability S ...
Debian Bug report logs - #907983 lcms2: CVE-2018-16435 Package: src:lcms2; Maintainer for src:lcms2 is Thomas Weber <tweber@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 4 Sep 2018 19:09:02 UTC Severity: grave Tags: patch, security, upstream Found in version lcms2/28-4 Fixed in vers ...
Several security issues were fixed in Little CMS ...
Several security issues were fixed in Little CMS ...