CVE Vulnerabilities

CVE-2008-5317

Published: Dec 03, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain number of entries value, which is interpreted improperly, leading to an allocation of insufficient memory.

Affected Software

NameVendorStart VersionEnd Version
LcmsLittlecms*1.16 (including)
LcmsLittlecms1.07 (including)1.07 (including)
LcmsLittlecms1.08 (including)1.08 (including)
LcmsLittlecms1.09 (including)1.09 (including)
LcmsLittlecms1.10 (including)1.10 (including)
LcmsLittlecms1.11 (including)1.11 (including)
LcmsLittlecms1.12 (including)1.12 (including)
LcmsLittlecms1.13 (including)1.13 (including)
LcmsLittlecms1.14 (including)1.14 (including)
LcmsLittlecms1.15 (including)1.15 (including)
Little_cms_color_engineLittlecms*1.16 (including)
Little_cms_color_engineLittlecms1.07 (including)1.07 (including)
Little_cms_color_engineLittlecms1.08 (including)1.08 (including)
Little_cms_color_engineLittlecms1.09 (including)1.09 (including)
Little_cms_color_engineLittlecms1.10 (including)1.10 (including)
Little_cms_color_engineLittlecms1.11 (including)1.11 (including)
Little_cms_color_engineLittlecms1.12 (including)1.12 (including)
Little_cms_color_engineLittlecms1.13 (including)1.13 (including)
Little_cms_color_engineLittlecms1.14 (including)1.14 (including)
Little_cms_color_engineLittlecms1.15 (including)1.15 (including)
Red Hat Enterprise Linux 5RedHatlcms-0:1.15-1.2.2.el5_2.2*
LcmsUbuntudapper*
LcmsUbuntugutsy*
LcmsUbuntuhardy*
LcmsUbuntuintrepid*
LcmsUbuntuupstream*

References