PT-2009-6703 · Little Cms+1 · Lcms+5

Chris Evans

·

Published

1970-01-01

·

Updated

2024-11-19

·

CVE-2009-0723

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions liblcms1 versions prior to 1.18 liblcms1-dev versions prior to 1.18 lcms versions prior to 1.18 lcms-devel versions prior to 1.18 lcms-utils versions prior to 1.18
Description The issue involves multiple integer overflows in LittleCMS, which can be exploited by context-dependent attackers to execute arbitrary code via a crafted image file, leading to a heap-based buffer overflow. This can result in the disruption of confidentiality, integrity, and availability of protected information. The exploitation of these vulnerabilities can be carried out remotely.
Recommendations For liblcms1 versions prior to 1.18, update to version 1.18 or later. For liblcms1-dev versions prior to 1.18, update to version 1.18 or later. For lcms versions prior to 1.18, update to version 1.18 or later. For lcms-devel versions prior to 1.18, update to version 1.18 or later. For lcms-utils versions prior to 1.18, update to version 1.18 or later. As a temporary workaround, consider avoiding the use of crafted image files that could trigger a heap-based buffer overflow until a patch is available.

Exploit

Fix

Integer Overflow

Memory Leak

Weakness Enumeration

Related Identifiers

BDU:2015-03025
BDU:2015-03026
BDU:2015-03027
BDU:2015-06297
BDU:2015-06299
BDU:2015-09381
CVE-2009-0723
DSA-1745-1
DSA-1769-1
RHSA-2009:0339
RHSA-2009:0377
RHSA-2009_0339
RHSA-2009_0377

Affected Products

Red Hat
Lcms
Lcms-Devel
Lcms-Utils
Liblcms1
Liblcms1-Dev