PT-2007-4057 · Lcms · Little Cms

Chris Evans

·

Published

2007-05-17

·

Updated

2017-07-29

·

CVE-2007-2741

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Little CMS (lcms) versions prior to 1.15
Description The issue is a stack-based buffer overflow that allows remote attackers to execute arbitrary code or cause a denial of service, resulting in an application crash. This can be achieved via a crafted ICC profile in a JPG file.
Recommendations For versions prior to 1.15, update to version 1.15 or later to resolve the issue.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-2741

Affected Products

Little Cms