CVE-2013-7455

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:littlecms:little_cms_color_engine:2.0:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:2.1:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:2.2:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:2.3:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:2.4:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:2.5:*:*:*:*:*:*:*

History

21 Nov 2024, 02:01

Type Values Removed Values Added
References () http://www.kb.cert.org/vuls/id/369800 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/369800 - Third Party Advisory, US Government Resource
References () http://www.ubuntu.com/usn/USN-2961-1 - () http://www.ubuntu.com/usn/USN-2961-1 -
References () https://github.com/mm2/Little-CMS/commit/fefaaa43c382eee632ea3ad0cfa915335140e1db - () https://github.com/mm2/Little-CMS/commit/fefaaa43c382eee632ea3ad0cfa915335140e1db -
References () https://penteston.com/OSVDB-105462 - () https://penteston.com/OSVDB-105462 -

Information

Published : 2016-05-07 10:59

Updated : 2024-11-21 02:01


NVD link : CVE-2013-7455

Mitre link : CVE-2013-7455

CVE.ORG link : CVE-2013-7455


JSON object : View

Products Affected

littlecms

  • little_cms_color_engine