PT-2017-7778 · Little Cms+5 · Little Cms+5

Ibrahim El-Sayed

·

Publicado

2016-10-19

·

Atualizado

2024-06-15

·

CVE-2016-10165

CVSS v3.1

7.1

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Little CMS (aka lcms2) (affected versions not specified)
Description The issue allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read. This is due to the Type MLU Read function in cmstypes.c.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-44601
CESA-2016_2079
CESA-2016_2658
CVE-2016-10165
DLA-803-1
DSA-3774-1
OPENSUSE-SU-2017_2998-1
OPENSUSE-SU-2018_0042-1
OPENSUSE-SU-2024:10876-1
RHSA-2016:2079
RHSA-2016:2658
RHSA-2016_2079
RHSA-2016_2658
RHSA-2017:2999
RHSA-2017:3046
RHSA-2017:3264
RHSA-2017:3267
RHSA-2017:3268
RHSA-2017:3453
RHSA-2017_2999
RHSA-2017_3046
RHSA-2017_3264
RHSA-2017_3267
RHSA-2017_3268
SUSE-SU-2017:2989-1
SUSE-SU-2017:3411-1
SUSE-SU-2017:3440-1
SUSE-SU-2017:3455-1
SUSE-SU-2017_2989-1
SUSE-SU-2017_3411-1
SUSE-SU-2017_3440-1
SUSE-SU-2017_3455-1
SUSE-SU-2018:0005-1
SUSE-SU-2018:0061-1
SUSE-SU-2018:3545-1
SUSE-SU-2018_0061-1
SUSE-SU-2018_3545-1
USN-3770-1
USN-3770-2

Produtos afetados

Centos
Java Platform
Little Cms
Red Hat
Suse
Ubuntu