PT-2018-10664 · Little Cms+1 · Little Cms+1
Xiaoqx
·
Published
2018-05-30
·
Updated
2024-08-05
·
CVE-2018-11556
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Little CMS version 2.9
Description
The issue is related to an out-of-bounds write in the
cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a, which can be triggered via a crafted TIFF file. However, the Little CMS developers do not consider this a vulnerability in the lcms2 library itself, as it depends on LIBTIFF only for building sample programs and the issue cannot be reproduced on the lcms2 library.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Little Cms