CVE-2009-0733
published 2009-03-23CVE-2009-0733: Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK…
PriorityP342critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.53%
91.9th percentile
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gimp | gimp | < 2.9.2 | 2.9.2 |
| littlecms | little_cms | <= 1.17 | — |
| mozilla | firefox | — | — |
| sun | openjdk | <= 7 | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mm82-c2wc-w6j7: Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1
ghsa_unreviewed·2022-05-02
CVE-2009-0733 [HIGH] CWE-787 GHSA-mm82-c2wc-w6j7: Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.
Ubuntu
LittleCMS vulnerabilities
vendor_ubuntu·2009-03-23·CVSS 4.3
CVE-2009-0581 [MEDIUM] LittleCMS vulnerabilities
Title: LittleCMS vulnerabilities
Summary: LittleCMS vulnerabilities
Chris Evans discovered that LittleCMS did not properly handle certain error
conditions, resulting in a large memory leak. If a user or automated system
were tricked into processing an image with malicious ICC tags, a remote
attacker could cause a denial of service. (CVE-2009-0581)
Chris Evans discovered that LittleCMS contained multiple integer overflows.
If a user or automated system were tricked into processing an image with
malicious ICC tags, a remote attacker could crash applications linked
against liblcms1, leading to a denial of service, or possibly execute
arbitrary code with user privileges. (CVE-2009-0723)
Chris Evans discovered that LittleCMS did not properly perform bounds
checking, leading to a buffer over
Red Hat
LittleCms lack of upper-bounds check on sizes
vendor_redhat·2009-03-19·CVSS 9.3
CVE-2009-0733 [CRITICAL] LittleCms lack of upper-bounds check on sizes
LittleCms lack of upper-bounds check on sizes
Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-0733 postgresql: Integer overflow in hash table size calculation
bugzilla·2009-12-11·CVSS 3.5
CVE-2010-0733 [LOW] CVE-2010-0733 postgresql: Integer overflow in hash table size calculation
CVE-2010-0733 postgresql: Integer overflow in hash table size calculation
An integer overflow flaw was found in the way postgresql
used to calculate size for the hashtable for joined
relations. An attacker could formulate a specially-crafted
sql query, which once processed would lead to denial of
service (postgresql daemon crash).
Upstream bug report:
[1] http://archives.postgresql.org/pgsql-bugs/2009-10/msg00277.php
References:
[2] http://archives.postgresql.org/pgsql-bugs/2009-10/msg00287.php
[3] http://archives.postgresql.org/pgsql-bugs/2009-10/msg00310.php
[4] http://archives.postgresql.org/pgsql-bugs/2009-10/msg00289.php
Upstream patch:
git clone git://git.postgresql.org/git/postgresql.git
cd postgresql && git show 64b057e6823655fb6c5d1f24a28f236b94dd6c54
Credit:
Bernt Marius Joh
Bugzilla
CVE-2009-0733 LittleCms lack of upper-bounds check on sizes
bugzilla·2009-02-26·CVSS 9.3
CVE-2009-0733 [CRITICAL] CVE-2009-0733 LittleCms lack of upper-bounds check on sizes
CVE-2009-0733 LittleCms lack of upper-bounds check on sizes
Chris Evans discovered a flaw in how LittleCms checks certain upper-bounds sizes. This flaw could potentially lead to arbitrary code execution in applications that use the system LittleCms library, or embed the source into their application.
Acknowledgements:
Red Hat would like to thank Chris Evans from the Google Security Team for
reporting these issues.
Discussion:
Lifting embargo
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 5
Via RHSA-2009:0339 https://rhn.redhat.com/errata/RHSA-2009-0339.html
---
lcms-1.18-0.1.beta2.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/lcms-1.18-0.1.beta2.fc10
---
lcms-1.18-0.1.beta2.fc9 has been submitted a
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.htmlhttp://scary.beasts.org/security/CESA-2009-003.htmlhttp://scarybeastsecurity.blogspot.com/2009/03/littlecms-vulnerabilities.htmlhttp://secunia.com/advisories/34367http://secunia.com/advisories/34382http://secunia.com/advisories/34400http://secunia.com/advisories/34408http://secunia.com/advisories/34418http://secunia.com/advisories/34442http://secunia.com/advisories/34450http://secunia.com/advisories/34454http://secunia.com/advisories/34463http://secunia.com/advisories/34632http://secunia.com/advisories/34675http://secunia.com/advisories/34782http://security.gentoo.org/glsa/glsa-200904-19.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.487438http://www.debian.org/security/2009/dsa-1745http://www.debian.org/security/2009/dsa-1769http://www.mandriva.com/security/advisories?name=MDVSA-2009:121http://www.mandriva.com/security/advisories?name=MDVSA-2009:137http://www.mandriva.com/security/advisories?name=MDVSA-2009:162http://www.ocert.org/advisories/ocert-2009-003.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0339.htmlhttp://www.securityfocus.com/archive/1/502018/100/0/threadedhttp://www.securityfocus.com/archive/1/502031/100/0/threadedhttp://www.securityfocus.com/bid/34185http://www.securitytracker.com/id?1021869http://www.ubuntu.com/usn/USN-744-1http://www.vupen.com/english/advisories/2009/0775https://bugzilla.redhat.com/show_bug.cgi?id=487512https://exchange.xforce.ibmcloud.com/vulnerabilities/49330https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9742https://rhn.redhat.com/errata/RHSA-2009-0377.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00794.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00799.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00811.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00851.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00856.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00857.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00921.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.htmlhttp://scary.beasts.org/security/CESA-2009-003.htmlhttp://scarybeastsecurity.blogspot.com/2009/03/littlecms-vulnerabilities.htmlhttp://secunia.com/advisories/34367http://secunia.com/advisories/34382http://secunia.com/advisories/34400http://secunia.com/advisories/34408http://secunia.com/advisories/34418http://secunia.com/advisories/34442http://secunia.com/advisories/34450http://secunia.com/advisories/34454http://secunia.com/advisories/34463http://secunia.com/advisories/34632http://secunia.com/advisories/34675http://secunia.com/advisories/34782http://security.gentoo.org/glsa/glsa-200904-19.xmlhttp://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.487438http://www.debian.org/security/2009/dsa-1745http://www.debian.org/security/2009/dsa-1769http://www.mandriva.com/security/advisories?name=MDVSA-2009:121http://www.mandriva.com/security/advisories?name=MDVSA-2009:137http://www.mandriva.com/security/advisories?name=MDVSA-2009:162http://www.ocert.org/advisories/ocert-2009-003.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0339.htmlhttp://www.securityfocus.com/archive/1/502018/100/0/threadedhttp://www.securityfocus.com/archive/1/502031/100/0/threadedhttp://www.securityfocus.com/bid/34185http://www.securitytracker.com/id?1021869http://www.ubuntu.com/usn/USN-744-1http://www.vupen.com/english/advisories/2009/0775https://bugzilla.redhat.com/show_bug.cgi?id=487512https://exchange.xforce.ibmcloud.com/vulnerabilities/49330https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9742https://rhn.redhat.com/errata/RHSA-2009-0377.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00794.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00799.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00811.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00851.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00856.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00857.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00921.html
2009-03-23
Published