CVE-2018-16435 PUBLISHED

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

EPSS 0.45% · 63.5th percentile

Risk Scores

EPSS Score
0.45%
63.5th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSoxide-qt1.9.5-0ubuntu1, 1.17.9-0ubuntu0.16.04.1, 1.17.7-0ubuntu0.16.04.1
Ubuntu:18.04:LTSchromium-browser68.0.3440.106-0ubuntu0.18.04.1, 68.0.3440.75-0ubuntu0.18.04.1, 67.0.3396.99-0ubuntu0.18.04.1
Ubuntu:16.04:LTSlcms20, 2.6-3ubuntu2
Ubuntu:18.04:LTSlcms20, 2.7-1ubuntu1, 2.8-4
Ubuntu:14.04:LTSlcms22.5-0ubuntu2, 0, 2.5-0ubuntu1
Ubuntu:16.04:LTSchromium-browser62.0.3202.94-0ubuntu0.16.04.1317, 62.0.3202.89-0ubuntu0.16.04.1315, 62.0.3202.75-0ubuntu0.16.04.1313

Timeline

References

Open in Interactive Console →