CVE-2016-10165 PUBLISHED

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

EPSS 0.87% · 75.1th percentile

Risk Scores

EPSS Score
0.87%
75.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlcms20, 2.7-1ubuntu1
Ubuntu:14.04:LTSopenjdk-77u55-2.4.7-1ubuntu1, 7u79-2.5.5-0ubuntu0.14.04.2, 7u79-2.5.6-0ubuntu1.14.04.1
Ubuntu:16.04:LTSlcms22.6-3ubuntu2, 0
Ubuntu:14.04:LTSlcms22.5-0ubuntu4.1, 2.5-0ubuntu3, 0

Timeline

References

Open in Interactive Console →