CVE-2016-10165 – lcms2: Out-of-bounds read in Type_MLU_Read()
https://notcve.org/view.php?id=CVE-2016-10165
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read. La función Type_MLU_Read en cmstypes.c en Little CMS (también conocido como lcms2) permite a atacantes remotos obtener información sensible o provocar una denegación de servicio a través de una imagen con un perfil ICC manipulado, lo que desencadena una lectura de memoria dinámica fuera de límites. • http://lists.opensuse.org/opensuse-updates/2017-01/msg00174.html http://rhn.redhat.com/errata/RHSA-2016-2079.html http://rhn.redhat.com/errata/RHSA-2016-2658.html http://www.debian.org/security/2017/dsa-3774 http://www.openwall.com/lists/oss-security/2017/01/23/1 http://www.openwall.com/lists/oss-security/2017/01/25/14 http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html http://www.securityfocus.com/bid/95808 http://www.securitytracker.com/id& • CWE-125: Out-of-bounds Read •
CVE-2013-7455
https://notcve.org/view.php?id=CVE-2013-7455
Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler. Vulnerabilidad de liberación doble de memoria en la función DefaultICCintents en cmscnvrt.c en liblcms2 en Little CMS 2.x en versiones anteriores a 2.6 permite a atacantes remotos ejecutar código arbitrario a través de un perfil ICC mal formado que desencadena un error en el manejador de intent por defecto. • http://www.kb.cert.org/vuls/id/369800 http://www.ubuntu.com/usn/USN-2961-1 https://github.com/mm2/Little-CMS/commit/fefaaa43c382eee632ea3ad0cfa915335140e1db https://penteston.com/OSVDB-105462 •
CVE-2013-4276
https://notcve.org/view.php?id=CVE-2013-4276
Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to cause a denial of service (crash) via a crafted (1) ICC color profile to the icctrans utility or (2) TIFF image to the tiffdiff utility. Múltiples vulnerabilidades buffer overflow de pila en LittleCMS (tambien conocido como lcms o liblcms) 1.19 y anteriores, permite a un atacante remoto causar una denegación de servicio (caída) a través de (1) un perfil ICC color manipulado en la utilidad icctrans, o (2) una imágen TIFF manipulada en la utilidad tiffdiff. • http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=718682 http://lists.opensuse.org/opensuse-updates/2013-10/msg00021.html http://lists.opensuse.org/opensuse-updates/2013-10/msg00029.html http://www.openwall.com/lists/oss-security/2013/08/22/3 http://www.securityfocus.com/bid/61607 https://bugzilla.redhat.com/show_bug.cgi?id=991757 https://bugzilla.redhat.com/show_bug.cgi?id=992975 https://usn.ubuntu.com/3770-2 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2013-4160
https://notcve.org/view.php?id=CVE-2013-4160
Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed. Little CMS (lcms2) anterior a la versión 2.5, tal como se usa en OpenJDK 7 y posiblemente otros productos, permite a a atacantes remotos provocar una denegación de servicio (dereferencia a puntero nulo y caída) a través de vectores relacionados con (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, y (5) cmsnamed. • http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-July/023895.html http://openwall.com/lists/oss-security/2013/07/18/7 http://openwall.com/lists/oss-security/2013/07/22/1 http://www.ubuntu.com/usn/USN-1911-1 https://bugzilla.novell.com/show_bug.cgi?id=826097#c9 https://github.com/mm2/Little-CMS/commit/91c2db7f2559be504211b283bc3a2c631d6f06d9 •
CVE-2008-5317 – lcms: unsigned -> signed integer cast issue in cmsAllocGamma
https://notcve.org/view.php?id=CVE-2008-5317
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory. Error de presencia de signo en entero en la función cmsAllocGamma en src/cmsgamma.c en Little cms color engine (alias lcms) en versiones anteriores a 1.17 que permite a los atacantes tener un impacto desconocido a través de un archivo que contiene un cierto número de valores de entrada, que son interpretados inapropiadamente, permitiendo una asignación de memoria insuficiente. • http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsgamma.c?view=diff&r1=1.16&r2=1.17 http://secunia.com/advisories/33066 http://secunia.com/advisories/33219 http://www.debian.org/security/2008/dsa-1684 http://www.openwall.com/lists/oss-security/2008/11/28/3 http://www.redhat.com/support/errata/RHSA-2009-0011.html http://www.securityfocus.com/bid/32708 https://exchange.xforce.ibmcloud.com/vulnerabilities/47120 https://oval.cisecurity.org/repository/search/definition • CWE-189: Numeric Errors •