Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted image file.
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Little_cms | Littlecms | * | 1.17 (including) |
Red Hat Enterprise Linux 5 | RedHat | lcms-0:1.18-0.1.beta1.el5_3.2 | * |
Red Hat Enterprise Linux 5 | RedHat | java-1.6.0-openjdk-1:1.6.0.0-0.30.b09.el5 | * |
Lcms | Ubuntu | dapper | * |
Lcms | Ubuntu | devel | * |
Lcms | Ubuntu | gutsy | * |
Lcms | Ubuntu | hardy | * |
Lcms | Ubuntu | intrepid | * |
Lcms | Ubuntu | upstream | * |