PT-2013-1268 · Little Cms+1 · Little Cms+2

Pedro Ribeiro

·

Published

2013-08-26

·

Updated

2024-06-15

·

CVE-2013-4276

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions LittleCMS versions 1.19 and earlier lcms versions prior to 2.6-r1
Description The issue concerns multiple stack-based buffer overflows in LittleCMS, allowing remote attackers to cause a denial of service via crafted files, such as ICC color profiles or TIFF images. This can lead to a crash of the system, disrupting the availability of protected information. The exploitation of these issues can be done remotely.
Recommendations For LittleCMS versions 1.19 and earlier: At the moment, there is no information about a newer version that contains a fix for this vulnerability. For lcms versions prior to 2.6-r1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-09774
CVE-2013-4276
MGASA-2013-0260
OPENSUSE-SU-2024:10340-1
SUSE-SU-2013_1743-1

Affected Products

Little Cms
Suse
Lcms