CVE-2013-4160
published 2014-01-21CVE-2013-4160: Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference…
PriorityP422medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.81%
84.9th percentile
Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.
Affected
19 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lcms2 | < lcms2 2.2+git20110628-2.3 (bookworm) | lcms2 2.2+git20110628-2.3 (bookworm) |
| littlecms | little_cms_color_engine | <= 2.4 | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6pgf-c4h7-m3qm: Little CMS (lcms2) before 2
ghsa_unreviewed·2022-05-17
CVE-2013-4160 [MEDIUM] GHSA-6pgf-c4h7-m3qm: Little CMS (lcms2) before 2
Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.
OSV
CVE-2013-4160: Little CMS (lcms2) before 2
osv·2014-01-21·CVSS 5.0
CVE-2013-4160 [MEDIUM] CVE-2013-4160: Little CMS (lcms2) before 2
Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.
Ubuntu
Ghostscript vulnerability
vendor_ubuntu·2013-07-31
CVE-2013-4160 Ghostscript vulnerability
Title: Ghostscript vulnerability
Summary: Ghostscript could be made to crash if it opened a specially crafted file.
USN-1911-1 fixed vulnerabilities in Little CMS. This update provides the
corresponding updates for Ghostscript.
Original advisory details:
It was discovered that Little CMS did not properly verify certain memory
allocations. If a user or automated system using Little CMS were tricked
into opening a specially crafted file, an attacker could cause Little CMS
to crash.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Little CMS vulnerability
vendor_ubuntu·2013-07-29
CVE-2013-4160 Little CMS vulnerability
Title: Little CMS vulnerability
Summary: Little CMS could be made to crash if it opened a specially crafted file.
It was discovered that Little CMS did not properly verify certain memory
allocations. If a user or automated system using Little CMS were tricked
into opening a specially crafted file, an attacker could cause Little CMS
to crash.
Instructions: After a standard system update you need to restart any applications that
uses Little CMS to make all the necessary changes.
Red Hat
CMS: multiple potential flaws
vendor_redhat·2013-06-20·CVSS 5.0
CVE-2013-4160 [MEDIUM] CMS: multiple potential flaws
CMS: multiple potential flaws
Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.
Package: lcms2 (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4160: lcms2 - Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products,...
vendor_debian·2013·CVSS 5.0
CVE-2013-4160 [MEDIUM] CVE-2013-4160: lcms2 - Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products,...
Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.
Scope: local
bookworm: resolved (fixed in 2.2+git20110628-2.3)
bullseye: resolved (fixed in 2.2+git20110628-2.3)
forky: resolved (fixed in 2.2+git20110628-2.3)
sid: resolved (fixed in 2.2+git20110628-2.3)
trixie: resolved (fixed in 2.2+git20110628-2.3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4160 lcms2: Little CMS: multiple potential flaws [epel-6]
bugzilla·2013-10-29·CVSS 5.0
CVE-2013-4160 [MEDIUM] CVE-2013-4160 lcms2: Little CMS: multiple potential flaws [epel-6]
CVE-2013-4160 lcms2: Little CMS: multiple potential flaws [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking bug for lcms2: se
Bugzilla
lcms2: CVE-2013-4160 Little CMS: multiple potential flaws [fedora-all]
bugzilla·2013-07-23·CVSS 5.0
CVE-2013-4160 [MEDIUM] lcms2: CVE-2013-4160 Little CMS: multiple potential flaws [fedora-all]
lcms2: CVE-2013-4160 Little CMS: multiple potential flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mu
Bugzilla
CVE-2013-4160 Little CMS: multiple potential flaws
bugzilla·2013-07-16·CVSS 5.0
CVE-2013-4160 [MEDIUM] CVE-2013-4160 Little CMS: multiple potential flaws
CVE-2013-4160 Little CMS: multiple potential flaws
A SUSE bug report [1] noted a number of potential flaws in lcms2 that were fixed in version 2.5. The changelog indicates:
* Added some checks for non-happy path, mostly failing mallocs
which was fixed via https://github.com/mm2/Little-CMS/commit/91c2db7f2559be504211b283bc3a2c631d6f06d9, however Stanislav looked at other changes between 2.4 and 2.5 and found some others that were suspect and could have potential security impact:
https://github.com/mm2/Little-CMS/commit/b0d5ffd4ad91cf8683ee106f13742db3dc66599a
https://github.com/mm2/Little-CMS/commit/06d4557477e7ab3330a24d69af4c67adcac9acdf
https://github.com/mm2/Little-CMS/commit/41d222df1bc6188131a8f46c32eab0a4d4cdf1b6
https://github.com/mm2/Little-CMS/commit/b0d5ffd4ad91cf8683ee106f13
http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-July/023895.htmlhttp://openwall.com/lists/oss-security/2013/07/18/7http://openwall.com/lists/oss-security/2013/07/22/1http://www.ubuntu.com/usn/USN-1911-1https://bugzilla.novell.com/show_bug.cgi?id=826097#c9https://github.com/mm2/Little-CMS/commit/91c2db7f2559be504211b283bc3a2c631d6f06d9http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2013-July/023895.htmlhttp://openwall.com/lists/oss-security/2013/07/18/7http://openwall.com/lists/oss-security/2013/07/22/1http://www.ubuntu.com/usn/USN-1911-1https://bugzilla.novell.com/show_bug.cgi?id=826097#c9https://github.com/mm2/Little-CMS/commit/91c2db7f2559be504211b283bc3a2c631d6f06d9
2014-01-21
Published