Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to cause a denial of service (crash) via a crafted (1) ICC color profile to the icctrans utility or (2) TIFF image to the tiffdiff utility.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade lcms. | Aug 30, 2017 | Sep 28, 2013 |
| Debian | — | Upgrade lcms | Jul 30, 2024 | Sep 28, 2013 |
| Gentoo Linux | — | Upgrade media-libs/lcms. | Oct 30, 2017 | Sep 28, 2013 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2 | May 29, 2017 | Sep 28, 2013 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 4, 2013 |
| Suse | — | Upgrade liblcms1-x86Upgrade python-lcmsUpgrade lcmsUpgrade liblcms-devel-32bitUpgrade liblcms1Upgrade sle-sdk-releaseUpgrade liblcms1-32bitUpgrade liblcms-devel | Dec 12, 2013 | Sep 28, 2013 |
| Ubuntu | — | Upgrade liblcms-utilsUpgrade liblcms2-utilsUpgrade liblcms1Upgrade liblcms2-2 | Oct 2, 2018 | Sep 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub