Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.
2008-12-03T17:30:00.540
2025-04-09T00:30:58.490
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | littlecms | lcms | ≤ 1.16 | Yes |
Application | littlecms | lcms | 1.07 | Yes |
Application | littlecms | lcms | 1.08 | Yes |
Application | littlecms | lcms | 1.09 | Yes |
Application | littlecms | lcms | 1.10 | Yes |
Application | littlecms | lcms | 1.11 | Yes |
Application | littlecms | lcms | 1.12 | Yes |
Application | littlecms | lcms | 1.13 | Yes |
Application | littlecms | lcms | 1.14 | Yes |
Application | littlecms | lcms | 1.15 | Yes |
Application | littlecms | little_cms_color_engine | ≤ 1.16 | Yes |
Application | littlecms | little_cms_color_engine | 1.07 | Yes |
Application | littlecms | little_cms_color_engine | 1.08 | Yes |
Application | littlecms | little_cms_color_engine | 1.09 | Yes |
Application | littlecms | little_cms_color_engine | 1.10 | Yes |
Application | littlecms | little_cms_color_engine | 1.11 | Yes |
Application | littlecms | little_cms_color_engine | 1.12 | Yes |
Application | littlecms | little_cms_color_engine | 1.13 | Yes |
Application | littlecms | little_cms_color_engine | 1.14 | Yes |
Application | littlecms | little_cms_color_engine | 1.15 | Yes |