PT-2009-6702 · Little Cms+1 · Liblcms+7

Chris Evans

·

Published

1970-01-01

·

Updated

2025-03-21

·

CVE-2009-0581

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LittleCMS versions prior to 1.18beta2 lcms versions prior to 1.18 liblcms versions prior to 1.18 liblcms1 versions prior to 1.18 liblcms1-dev versions prior to 1.18 lcms-devel versions prior to 1.18 lcms-utils versions prior to 1.18
Description The issue is related to a memory leak in LittleCMS, which can be exploited by context-dependent attackers to cause a denial of service, resulting in memory consumption and application crash via a crafted image file. The vulnerability can be exploited remotely, potentially leading to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For LittleCMS versions prior to 1.18beta2, update to version 1.18beta2 or later to resolve the issue. For lcms versions prior to 1.18, update to version 1.18 or later to resolve the issue. For liblcms versions prior to 1.18, update to version 1.18 or later to resolve the issue. For liblcms1 versions prior to 1.18, update to version 1.18 or later to resolve the issue. For liblcms1-dev versions prior to 1.18, update to version 1.18 or later to resolve the issue. For lcms-devel versions prior to 1.18, update to version 1.18 or later to resolve the issue. For lcms-utils versions prior to 1.18, update to version 1.18 or later to resolve the issue.

Exploit

Fix

DoS

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-03025
BDU:2015-03026
BDU:2015-03027
BDU:2015-06297
BDU:2015-06299
BDU:2015-09381
CVE-2009-0581
DSA-1745-1
DSA-1769-1
RHSA-2009:0339
RHSA-2009:0377
RHSA-2009_0339
RHSA-2009_0377

Affected Products

Little Cms
Red Hat
Lcms
Lcms-Devel
Lcms-Utils
Liblcms
Liblcms1
Liblcms1-Dev