- Description
- Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.
- Source
- cve@mitre.org
- NVD status
- Analyzed
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
- nvd@nist.gov
- CWE-787
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gimp:gimp:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "28CB30F0-E3AF-490A-B05B-0947A2BF717B",
"versionEndExcluding": "2.9.2"
},
{
"criteria": "cpe:2.3:a:mozilla:firefox:3.1:beta1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F72BFD4-000D-4B07-8261-C9F6839AD150"
},
{
"criteria": "cpe:2.3:a:sun:openjdk:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3BD10277-3747-438E-BB0F-CC7E71602FC1",
"versionEndIncluding": "7"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:littlecms:little_cms:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5DAF1951-51CA-4FCC-94EE-3713860D6598",
"versionEndIncluding": "1.17"
}
],
"operator": "OR"
}
]
}
]