CVE-2016-10165
published 2017-02-03CVE-2016-10165: The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an…
PriorityP427high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
2.77%
84.7th percentile
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | lcms2 | < lcms2 2.8-4 (bookworm) | lcms2 2.8-4 (bookworm) |
| littlecms | little_cms_color_engine | < 2.11 | 2.11 |
| netapp | active_iq_unified_manager | >= 7.3 | — |
| netapp | active_iq_unified_manager | >= 9.5 | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
| netapp | e-series_santricity_os_controller | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Little CMS vulnerabilities
vendor_ubuntu·2018-09-20·CVSS 4.3
CVE-2013-4276 [MEDIUM] Little CMS vulnerabilities
Title: Little CMS vulnerabilities
Summary: Several security issues were fixed in Little CMS.
USN-3770-1 fixed a vulnerability in Little CMS. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Pedro Ribeiro discoreved that Little CMS incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2013-4276)
Ibrahim El-Sayed discovered that Little CMS incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2016-10165)
Quang Nguyen discovered that Little CMS incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-16435)
Instructions: After a standard system update you need to restart
Ubuntu
Little CMS vulnerabilities
vendor_ubuntu·2018-09-20·CVSS 7.1
CVE-2016-10165 [HIGH] Little CMS vulnerabilities
Title: Little CMS vulnerabilities
Summary: Several security issues were fixed in Little CMS.
Ibrahim El-Sayed discovered that Little CMS incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2016-10165)
Quang Nguyen discovered that Little CMS incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-16435)
Instructions: After a standard system update you need to restart applications using Little
CMS to make all the necessary changes.
Red Hat
lcms2: Out-of-bounds read in Type_MLU_Read()
vendor_redhat·2016-08-15·CVSS 7.1
CVE-2016-10165 [HIGH] CWE-125 lcms2: Out-of-bounds read in Type_MLU_Read()
lcms2: Out-of-bounds read in Type_MLU_Read()
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
Package: lcms (Red Hat Enterprise Linux 5) - Not affected
Package: lcms (Red Hat Enterprise Linux 6) - Not affected
Package: lcms2 (Red Hat Enterprise Linux 7) - Will not fix
Package: lcms (Red Hat OpenShift Enterprise 2) - Not affected
Debian
CVE-2016-10165: lcms2 - The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote...
vendor_debian·2016·CVSS 7.1
CVE-2016-10165 [HIGH] CVE-2016-10165: lcms2 - The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote...
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
Scope: local
bookworm: resolved (fixed in 2.8-4)
bullseye: resolved (fixed in 2.8-4)
forky: resolved (fixed in 2.8-4)
sid: resolved (fixed in 2.8-4)
trixie: resolved (fixed in 2.8-4)
GHSA
GHSA-2j4r-j436-59p3: The Type_MLU_Read function in cmstypes
ghsa_unreviewed·2022-05-14
CVE-2016-10165 [HIGH] CWE-125 GHSA-2j4r-j436-59p3: The Type_MLU_Read function in cmstypes
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
OSV
lcms2 vulnerabilities
osv·2018-09-20·CVSS 7.1
CVE-2016-10165 [HIGH] lcms2 vulnerabilities
lcms2 vulnerabilities
Ibrahim El-Sayed discovered that Little CMS incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2016-10165)
Quang Nguyen discovered that Little CMS incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-16435)
OSV
CVE-2016-10165: The Type_MLU_Read function in cmstypes
osv·2017-02-03·CVSS 7.1
CVE-2016-10165 [HIGH] CVE-2016-10165: The Type_MLU_Read function in cmstypes
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-10165 lcms2: Out-of-bounds read in Type_MLU_Read() [fedora-all]
bugzilla·2016-08-16·CVSS 7.1
CVE-2016-10165 [HIGH] CVE-2016-10165 lcms2: Out-of-bounds read in Type_MLU_Read() [fedora-all]
CVE-2016-10165 lcms2: Out-of-bounds read in Type_MLU_Read() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
Bugzilla
CVE-2016-10165 lcms2: Out-of-bounds read in Type_MLU_Read()
bugzilla·2016-08-16·CVSS 7.1
CVE-2016-10165 [HIGH] CVE-2016-10165 lcms2: Out-of-bounds read in Type_MLU_Read()
CVE-2016-10165 lcms2: Out-of-bounds read in Type_MLU_Read()
An out-of-bounds read in cmstypes.c in Type_MLU_Read function was found, leading to heap memory leak triggered by crafted ICC profile.
Upstream patch:
https://github.com/mm2/Little-CMS/commit/5ca71a7bc18b6897ab21d815d15e218e204581e2
CVE request:
http://seclists.org/oss-sec/2016/q3/288
Discussion:
Created mingw-lcms2 tracking bugs for this issue:
Affects: fedora-all [bug 1367359]
---
Created lcms2 tracking bugs for this issue:
Affects: fedora-all [bug 1367358]
Affects: epel-5 [bug 1367360]
Affects: epel-6 [bug 1367361]
---
lcms2-2.8-2.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.
---
lcms2-2.8-2.fc24 has been pushed to the Fedora 24 stab
Bugzilla
CVE-2016-10165 mingw-lcms2: lcms2: Out-of-bounds read in Type_MLU_Read() [fedora-all]
bugzilla·2016-08-16·CVSS 7.1
CVE-2016-10165 [HIGH] CVE-2016-10165 mingw-lcms2: lcms2: Out-of-bounds read in Type_MLU_Read() [fedora-all]
CVE-2016-10165 mingw-lcms2: lcms2: Out-of-bounds read in Type_MLU_Read() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported vers
Bugzilla
CVE-2016-10165 lcms2: Out-of-bounds read in Type_MLU_Read() [epel-5]
bugzilla·2016-08-16·CVSS 7.1
CVE-2016-10165 [HIGH] CVE-2016-10165 lcms2: Out-of-bounds read in Type_MLU_Read() [epel-5]
CVE-2016-10165 lcms2: Out-of-bounds read in Type_MLU_Read() [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Discussi
Bugzilla
CVE-2016-10165 lcms2: Out-of-bounds read in Type_MLU_Read() [epel-6]
bugzilla·2016-08-16·CVSS 7.1
CVE-2016-10165 [HIGH] CVE-2016-10165 lcms2: Out-of-bounds read in Type_MLU_Read() [epel-6]
CVE-2016-10165 lcms2: Out-of-bounds read in Type_MLU_Read() [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Discussi
http://lists.opensuse.org/opensuse-updates/2017-01/msg00174.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2079.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2658.htmlhttp://www.debian.org/security/2017/dsa-3774http://www.openwall.com/lists/oss-security/2017/01/23/1http://www.openwall.com/lists/oss-security/2017/01/25/14http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/95808http://www.securitytracker.com/id/1039596https://access.redhat.com/errata/RHSA-2017:2999https://access.redhat.com/errata/RHSA-2017:3046https://access.redhat.com/errata/RHSA-2017:3264https://access.redhat.com/errata/RHSA-2017:3267https://access.redhat.com/errata/RHSA-2017:3268https://access.redhat.com/errata/RHSA-2017:3453https://github.com/mm2/Little-CMS/commit/5ca71a7bc18b6897ab21d815d15e218e204581e2https://security.netapp.com/advisory/ntap-20171019-0001/https://usn.ubuntu.com/3770-1/https://usn.ubuntu.com/3770-2/http://lists.opensuse.org/opensuse-updates/2017-01/msg00174.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2079.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2658.htmlhttp://www.debian.org/security/2017/dsa-3774http://www.openwall.com/lists/oss-security/2017/01/23/1http://www.openwall.com/lists/oss-security/2017/01/25/14http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/95808http://www.securitytracker.com/id/1039596https://access.redhat.com/errata/RHSA-2017:2999https://access.redhat.com/errata/RHSA-2017:3046https://access.redhat.com/errata/RHSA-2017:3264https://access.redhat.com/errata/RHSA-2017:3267https://access.redhat.com/errata/RHSA-2017:3268https://access.redhat.com/errata/RHSA-2017:3453https://github.com/mm2/Little-CMS/commit/5ca71a7bc18b6897ab21d815d15e218e204581e2https://security.netapp.com/advisory/ntap-20171019-0001/https://usn.ubuntu.com/3770-1/https://usn.ubuntu.com/3770-2/
2017-02-03
Published