CVE-2008-5317Lcms vulnerability

CWE-1897 documents6 sources
Severity
10.0CRITICALNVD
EPSS
0.9%
top 23.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 3
Latest updateMay 14

Description

Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6399-c226-99jr: Integer signedness error in the cmsAllocGamma function in src/cmsgamma2022-05-14
CVEList
CVE-2008-5317: Integer signedness error in the cmsAllocGamma function in src/cmsgamma2008-12-03

📋Vendor Advisories

3
Ubuntu
LittleCMS vulnerability2008-12-17
Ubuntu
LittleCMS vulnerability2008-10-14
Red Hat
lcms: unsigned -> signed integer cast issue in cmsAllocGamma2007-11-22

💬Community

1
Bugzilla
CVE-2008-5317 lcms: unsigned -> signed integer cast issue in cmsAllocGamma2008-11-28
CVE-2008-5317 — Littlecms Lcms vulnerability | cvebase