CVE-2013-4276
28.09.2013, 19:55
Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to cause a denial of service (crash) via a crafted (1) ICC color profile to the icctrans utility or (2) TIFF image to the tiffdiff utility.Enginsight
| Vendor | Product | Version |
|---|---|---|
| littlecms | little_cms_color_engine | 𝑥 ≤ 1.19 |
| littlecms | little_cms_color_engine | 1.07 |
| littlecms | little_cms_color_engine | 1.08 |
| littlecms | little_cms_color_engine | 1.09 |
| littlecms | little_cms_color_engine | 1.10 |
| littlecms | little_cms_color_engine | 1.11 |
| littlecms | little_cms_color_engine | 1.12 |
| littlecms | little_cms_color_engine | 1.13 |
| littlecms | little_cms_color_engine | 1.14 |
| littlecms | little_cms_color_engine | 1.15 |
| littlecms | little_cms_color_engine | 1.16 |
| littlecms | little_cms_color_engine | 1.17 |
| littlecms | little_cms_color_engine | 1.18 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ghostscript |
| ||||||||||||||||||||||||||||||||
| lcms |
| ||||||||||||||||||||||||||||||||
| lcms2 |
|
Common Weakness Enumeration
References