CVE-2016-10165
03.02.2017, 19:59
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| littlecms | little_cms_color_engine | 𝑥 < 2.11 |
| canonical | ubuntu_linux | 12.04 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| debian | debian_linux | 8.0 |
| opensuse | leap | 42.1 |
| redhat | satellite | 5.8 |
| redhat | enterprise_linux_desktop | 5.0 |
| redhat | enterprise_linux_desktop | 6.0 |
| redhat | enterprise_linux_desktop | 7.0 |
| redhat | enterprise_linux_server | 5.0 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_server | 7.0 |
| redhat | enterprise_linux_server_aus | 7.3 |
| redhat | enterprise_linux_server_aus | 7.4 |
| redhat | enterprise_linux_server_aus | 7.6 |
| redhat | enterprise_linux_server_aus | 7.7 |
| redhat | enterprise_linux_server_eus | 7.3 |
| redhat | enterprise_linux_server_eus | 7.4 |
| redhat | enterprise_linux_server_eus | 7.5 |
| redhat | enterprise_linux_server_eus | 7.6 |
| redhat | enterprise_linux_server_eus | 7.7 |
| redhat | enterprise_linux_server_tus | 7.3 |
| redhat | enterprise_linux_server_tus | 7.6 |
| redhat | enterprise_linux_server_tus | 7.7 |
| redhat | enterprise_linux_workstation | 5.0 |
| redhat | enterprise_linux_workstation | 6.0 |
| redhat | enterprise_linux_workstation | 7.0 |
| netapp | active_iq_unified_manager | 7.3 ≤ |
| netapp | active_iq_unified_manager | 9.5 ≤ |
| netapp | e-series_santricity_management | - |
| netapp | e-series_santricity_management | - |
| netapp | e-series_santricity_management | - |
| netapp | e-series_santricity_os_controller | 11.0 |
| netapp | e-series_santricity_os_controller | 11.0.0 |
| netapp | e-series_santricity_os_controller | 11.20 |
| netapp | e-series_santricity_os_controller | 11.25 |
| netapp | e-series_santricity_os_controller | 11.30 |
| netapp | e-series_santricity_os_controller | 11.30.5r3:r3 |
| netapp | e-series_santricity_os_controller | 11.40 |
| netapp | e-series_santricity_os_controller | 11.40.3r2:r2 |
| netapp | e-series_santricity_os_controller | 11.40.5 |
| netapp | e-series_santricity_os_controller | 11.50.1 |
| netapp | e-series_santricity_os_controller | 11.50.2 |
| netapp | e-series_santricity_os_controller | 11.50.2:p1 |
| netapp | e-series_santricity_os_controller | 11.60 |
| netapp | e-series_santricity_os_controller | 11.60.0 |
| netapp | e-series_santricity_os_controller | 11.60.1 |
| netapp | e-series_santricity_os_controller | 11.60.3 |
| netapp | e-series_santricity_os_controller | 11.70.1 |
| netapp | e-series_santricity_os_controller | 11.70.2 |
| netapp | oncommand_balance | - |
| netapp | oncommand_insight | - |
| netapp | oncommand_performance_manager | - |
| netapp | oncommand_shift | - |
| netapp | oncommand_unified_manager | - |
| netapp | oncommand_unified_manager | 7.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| lcms2 |
| ||||||||||||||
| openjdk-7 |
| ||||||||||||||
| openjdk-8 |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| java-1_7_0-openjdk |
| ||||||||||||||||||||||||||||||||||||||||||||||
| java-1_7_0-openjdk-demo |
| ||||||||||||||||||||||||||||||||||||||||||||||
| java-1_7_0-openjdk-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||
| java-1_7_0-openjdk-headless |
| ||||||||||||||||||||||||||||||||||||||||||||||
| java-1_8_0-openjdk |
| ||||||||||||||||||||||||||||||||||||||||||||||
| java-1_8_0-openjdk-demo |
| ||||||||||||||||||||||||||||||||||||||||||||||
| java-1_8_0-openjdk-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||
| java-1_8_0-openjdk-headless |
| ||||||||||||||||||||||||||||||||||||||||||||||
| lcms2 |
| ||||||||||||||||||||||||||||||||||||||||||||||
| liblcms2-2 |
| ||||||||||||||||||||||||||||||||||||||||||||||
| liblcms2-2-32bit |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||
|---|---|---|---|---|---|
| java-1.7.0-openjdk |
| ||||
| java-1.7.0-openjdk-accessibility |
| ||||
| java-1.7.0-openjdk-demo |
| ||||
| java-1.7.0-openjdk-devel |
| ||||
| java-1.7.0-openjdk-headless |
| ||||
| java-1.7.0-openjdk-javadoc |
| ||||
| java-1.7.0-openjdk-src |
| ||||
| java-1.7.1-ibm |
| ||||
| java-1.7.1-ibm-demo |
| ||||
| java-1.7.1-ibm-devel |
| ||||
| java-1.7.1-ibm-jdbc |
| ||||
| java-1.7.1-ibm-plugin |
| ||||
| java-1.7.1-ibm-src |
| ||||
| java-1.8.0-ibm |
| ||||
| java-1.8.0-ibm-demo |
| ||||
| java-1.8.0-ibm-devel |
| ||||
| java-1.8.0-ibm-jdbc |
| ||||
| java-1.8.0-ibm-plugin |
| ||||
| java-1.8.0-ibm-src |
| ||||
| java-1.8.0-openjdk |
| ||||
| java-1.8.0-openjdk-accessibility |
| ||||
| java-1.8.0-openjdk-accessibility-debug |
| ||||
| java-1.8.0-openjdk-debug |
| ||||
| java-1.8.0-openjdk-demo |
| ||||
| java-1.8.0-openjdk-demo-debug |
| ||||
| java-1.8.0-openjdk-devel |
| ||||
| java-1.8.0-openjdk-devel-debug |
| ||||
| java-1.8.0-openjdk-headless |
| ||||
| java-1.8.0-openjdk-headless-debug |
| ||||
| java-1.8.0-openjdk-javadoc |
| ||||
| java-1.8.0-openjdk-javadoc-debug |
| ||||
| java-1.8.0-openjdk-src |
| ||||
| java-1.8.0-openjdk-src-debug |
|
Common Weakness Enumeration
References