PT-2018-10664 · Little Cms+1 · Little Cms+1

Xiaoqx

·

Publicado

2018-05-30

·

Atualizado

2024-08-05

·

CVE-2018-11556

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Little CMS version 2.9
Description The issue is related to an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a, which can be triggered via a crafted TIFF file. However, the Little CMS developers do not consider this a vulnerability in the lcms2 library itself, as it depends on LIBTIFF only for building sample programs and the issue cannot be reproduced on the lcms2 library.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-2055
CVE-2018-11556

Produtos afetados

Alt Linux
Little Cms