Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade lcms-develUpgrade python-lcmsUpgrade lcms | Dec 1, 2016 | Dec 3, 2008 |
| Oracle_linux | — | Upgrade lcms-develUpgrade lcmsUpgrade python-lcms | Oct 16, 2024 | Dec 3, 2008 |
| Ubuntu | — | Upgrade liblcms1 | Nov 8, 2024 | Dec 3, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub