CVE-2013-7455
published 2016-05-07CVE-2013-7455: Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary…
PriorityP353critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
6.23%
92.7th percentile
Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lcms2 | < lcms2 2.6-1 (bookworm) | lcms2 2.6-1 (bookworm) |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
| littlecms | little_cms_color_engine | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
lcms2: double free on error recovering
vendor_redhat·2016-05-04·CVSS 9.8
CVE-2013-7455 [CRITICAL] lcms2: double free on error recovering
lcms2: double free on error recovering
Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.
Package: lcms2 (Red Hat Enterprise Linux 7) - Not affected
Ubuntu
Little CMS vulnerability
vendor_ubuntu·2016-05-04
CVE-2013-7455 Little CMS vulnerability
Title: Little CMS vulnerability
Summary: Applications using the Little CMS library could be made to crash or
run programs as your login if it opened a specially crafted file.
It was discovered that a double free() could occur when the intent handling
code in the Little CMS library detected an error. An attacker could use
this to specially craft a file that caused an application using the Little
CMS library to crash or possibly execute arbitrary code.
Instructions: After a standard system update you need to restart applications using
Little CMS to make all the necessary changes.
Debian
CVE-2013-7455: lcms2 - Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in lib...
vendor_debian·2013·CVSS 9.8
CVE-2013-7455 [CRITICAL] CVE-2013-7455: lcms2 - Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in lib...
Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.
Scope: local
bookworm: resolved (fixed in 2.6-1)
bullseye: resolved (fixed in 2.6-1)
forky: resolved (fixed in 2.6-1)
sid: resolved (fixed in 2.6-1)
trixie: resolved (fixed in 2.6-1)
GHSA
GHSA-wv94-377g-rv89: Double free vulnerability in the DefaultICCintents function in cmscnvrt
ghsa_unreviewed·2022-05-17
CVE-2013-7455 [CRITICAL] GHSA-wv94-377g-rv89: Double free vulnerability in the DefaultICCintents function in cmscnvrt
Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.
OSV
CVE-2013-7455: Double free vulnerability in the DefaultICCintents function in cmscnvrt
osv·2016-05-07·CVSS 9.8
CVE-2013-7455 [CRITICAL] CVE-2013-7455: Double free vulnerability in the DefaultICCintents function in cmscnvrt
Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.
No detection rules found.
No public exploits indexed.
http://www.kb.cert.org/vuls/id/369800http://www.ubuntu.com/usn/USN-2961-1https://github.com/mm2/Little-CMS/commit/fefaaa43c382eee632ea3ad0cfa915335140e1dbhttps://penteston.com/OSVDB-105462http://www.kb.cert.org/vuls/id/369800http://www.ubuntu.com/usn/USN-2961-1https://github.com/mm2/Little-CMS/commit/fefaaa43c382eee632ea3ad0cfa915335140e1dbhttps://penteston.com/OSVDB-105462
2016-05-07
Published