CVE-2008-5316
published 2008-12-03CVE-2008-5316: Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown…
PriorityP334critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.78%
84.8th percentile
Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| littlecms | lcms | <= 1.15 | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | little_cms_color_engine | <= 1.15 | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LittleCMS vulnerability
vendor_ubuntu·2008-10-14
CVE-2007-2741 LittleCMS vulnerability
Title: LittleCMS vulnerability
Summary: LittleCMS vulnerability
Chris Evans discovered that certain ICC operations in lcms were not
correctly bounds-checked. If a user or automated system were tricked
into processing an image with malicious ICC tags, a remote attacker could
crash applications linked against liblcms1, leading to a denial of service,
or possibly execute arbitrary code with user privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
lcms: insufficient input validation in ReadEmbeddedTextTag
vendor_redhat·2007-11-22·CVSS 9.3
CVE-2008-5316 [CRITICAL] CWE-20 lcms: insufficient input validation in ReadEmbeddedTextTag
lcms: insufficient input validation in ReadEmbeddedTextTag
Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.
GHSA
GHSA-hwr4-gr5c-2vfm: Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1
ghsa_unreviewed·2022-05-17·CVSS 9.3
CVE-2008-5316 [CRITICAL] CWE-119 GHSA-hwr4-gr5c-2vfm: Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1
Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.
No detection rules found.
No public exploits indexed.
http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsio1.c?r1=1.33&r2=1.34http://secunia.com/advisories/33066http://www.debian.org/security/2008/dsa-1684http://www.openwall.com/lists/oss-security/2008/11/28/3http://www.redhat.com/support/errata/RHSA-2009-0011.htmlhttp://www.securityfocus.com/bid/32708https://exchange.xforce.ibmcloud.com/vulnerabilities/47119https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10531http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsio1.c?r1=1.33&r2=1.34http://secunia.com/advisories/33066http://www.debian.org/security/2008/dsa-1684http://www.openwall.com/lists/oss-security/2008/11/28/3http://www.redhat.com/support/errata/RHSA-2009-0011.htmlhttp://www.securityfocus.com/bid/32708https://exchange.xforce.ibmcloud.com/vulnerabilities/47119https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10531
2008-12-03
Published