CVE-2009-0793
published 2009-04-09CVE-2009-0793: cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer…
PriorityP419medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
4.83%
91.0th percentile
cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| littlecms | lcms | — | — |
| sun | openjdk | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Little CMS vulnerability
vendor_ubuntu·2011-01-12·CVSS 4.3
CVE-2009-0793 [MEDIUM] Little CMS vulnerability
Title: Little CMS vulnerability
It was discovered that a NULL pointer dereference in the code for
handling transformations of monochrome profiles could allow an attacker
to cause a denial of service through a specially crafted image.
(CVE-2009-0793)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
lcms: Null pointer dereference (DoS) by handling transformations of monochrome profiles
vendor_redhat·2009-04-02·CVSS 4.3
CVE-2009-0793 [MEDIUM] CWE-476 lcms: Null pointer dereference (DoS) by handling transformations of monochrome profiles
lcms: Null pointer dereference (DoS) by handling transformations of monochrome profiles
cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."
Package: lcms (Red Hat Enterprise Linux 5) - Will not fix
GHSA
GHSA-mqm3-p699-wmxx: cmsxform
ghsa_unreviewed·2022-05-02
CVE-2009-0793 [MEDIUM] CWE-20 GHSA-mqm3-p699-wmxx: cmsxform
cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/34623http://secunia.com/advisories/34632http://secunia.com/advisories/34634http://secunia.com/advisories/34635http://secunia.com/advisories/34675http://secunia.com/advisories/34782http://secunia.com/advisories/35048http://secunia.com/advisories/42870http://security.gentoo.org/glsa/glsa-200904-19.xmlhttp://www.debian.org/security/2009/dsa-1769http://www.mandriva.com/security/advisories?name=MDVSA-2009:121http://www.mandriva.com/security/advisories?name=MDVSA-2009:137http://www.mandriva.com/security/advisories?name=MDVSA-2009:162http://www.securityfocus.com/bid/34411http://www.securityfocus.com/bid/34420http://www.ubuntu.com/usn/USN-1043-1http://www.vupen.com/english/advisories/2009/0963http://www.vupen.com/english/advisories/2009/0964http://www.vupen.com/english/advisories/2011/0087https://bugzilla.redhat.com/show_bug.cgi?id=492353https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11340https://rhn.redhat.com/errata/RHSA-2009-0377.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00203.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00204.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-May/msg00233.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-May/msg00285.htmlhttp://secunia.com/advisories/34623http://secunia.com/advisories/34632http://secunia.com/advisories/34634http://secunia.com/advisories/34635http://secunia.com/advisories/34675http://secunia.com/advisories/34782http://secunia.com/advisories/35048http://secunia.com/advisories/42870http://security.gentoo.org/glsa/glsa-200904-19.xmlhttp://www.debian.org/security/2009/dsa-1769http://www.mandriva.com/security/advisories?name=MDVSA-2009:121http://www.mandriva.com/security/advisories?name=MDVSA-2009:137http://www.mandriva.com/security/advisories?name=MDVSA-2009:162http://www.securityfocus.com/bid/34411http://www.securityfocus.com/bid/34420http://www.ubuntu.com/usn/USN-1043-1http://www.vupen.com/english/advisories/2009/0963http://www.vupen.com/english/advisories/2009/0964http://www.vupen.com/english/advisories/2011/0087https://bugzilla.redhat.com/show_bug.cgi?id=492353https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11340https://rhn.redhat.com/errata/RHSA-2009-0377.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00203.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00204.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-May/msg00233.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-May/msg00285.html
2009-04-09
Published