CVE-2009-0723

Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow.  NOTE: some of these details are obtained from third party information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
VendorProductVersion
gimpgimp
𝑥
< 2.9.2
mozillafirefox
3.1:beta1
sunopenjdk
𝑥
≤ 7
littlecmslittle_cms
𝑥
≤ 1.17
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lcms
intrepid
Fixed 1.16-10ubuntu0.2
released
hardy
Fixed 1.16-7ubuntu1.2
released
gutsy
Fixed 1.16-5ubuntu3.2
released
dapper
Fixed 1.13-1ubuntu0.2
released
References