PT-2018-10664 · Little Cms+1 · Little Cms+1
Xiaoqx
·
Publicado
2018-05-30
·
Atualizado
2024-08-05
·
CVE-2018-11556
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Little CMS version 2.9
Description
The issue is related to an out-of-bounds write in the
cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a, which can be triggered via a crafted TIFF file. However, the Little CMS developers do not consider this a vulnerability in the lcms2 library itself, as it depends on LIBTIFF only for building sample programs and the issue cannot be reproduced on the lcms2 library.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Little Cms