CVE-2008-5317
published 2008-12-03CVE-2008-5317: Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown…
PriorityP430critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.16%
80.2th percentile
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| littlecms | lcms | <= 1.16 | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | lcms | — | — |
| littlecms | little_cms_color_engine | <= 1.16 | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
LittleCMS vulnerability
vendor_ubuntu·2008-12-17
CVE-2008-5317 LittleCMS vulnerability
Title: LittleCMS vulnerability
Summary: LittleCMS vulnerability
It was discovered that certain gamma operations in lcms were not
correctly bounds-checked. If a user or automated system were tricked into
processing a malicious image, a remote attacker could crash applications
linked against liblcms1, leading to a denial of service, or possibly
execute arbitrary code with user privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Ubuntu
LittleCMS vulnerability
vendor_ubuntu·2008-10-14
CVE-2007-2741 LittleCMS vulnerability
Title: LittleCMS vulnerability
Summary: LittleCMS vulnerability
Chris Evans discovered that certain ICC operations in lcms were not
correctly bounds-checked. If a user or automated system were tricked
into processing an image with malicious ICC tags, a remote attacker could
crash applications linked against liblcms1, leading to a denial of service,
or possibly execute arbitrary code with user privileges.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Red Hat
lcms: unsigned -> signed integer cast issue in cmsAllocGamma
vendor_redhat·2007-11-22·CVSS 10.0
CVE-2008-5317 [CRITICAL] lcms: unsigned -> signed integer cast issue in cmsAllocGamma
lcms: unsigned -> signed integer cast issue in cmsAllocGamma
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.
GHSA
GHSA-6399-c226-99jr: Integer signedness error in the cmsAllocGamma function in src/cmsgamma
ghsa_unreviewed·2022-05-14
CVE-2008-5317 [HIGH] GHSA-6399-c226-99jr: Integer signedness error in the cmsAllocGamma function in src/cmsgamma
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.
No detection rules found.
No public exploits indexed.
http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsgamma.c?view=diff&r1=1.16&r2=1.17http://secunia.com/advisories/33066http://secunia.com/advisories/33219http://www.debian.org/security/2008/dsa-1684http://www.openwall.com/lists/oss-security/2008/11/28/3http://www.redhat.com/support/errata/RHSA-2009-0011.htmlhttp://www.securityfocus.com/bid/32708https://exchange.xforce.ibmcloud.com/vulnerabilities/47120https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10685https://usn.ubuntu.com/693-1/http://lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsgamma.c?view=diff&r1=1.16&r2=1.17http://secunia.com/advisories/33066http://secunia.com/advisories/33219http://www.debian.org/security/2008/dsa-1684http://www.openwall.com/lists/oss-security/2008/11/28/3http://www.redhat.com/support/errata/RHSA-2009-0011.htmlhttp://www.securityfocus.com/bid/32708https://exchange.xforce.ibmcloud.com/vulnerabilities/47120https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10685https://usn.ubuntu.com/693-1/
2008-12-03
Published