Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Little_cms_color_engine | Littlecms | * | 2.4 (including) |
Little_cms_color_engine | Littlecms | 1.07 (including) | 1.07 (including) |
Little_cms_color_engine | Littlecms | 1.08 (including) | 1.08 (including) |
Little_cms_color_engine | Littlecms | 1.09 (including) | 1.09 (including) |
Little_cms_color_engine | Littlecms | 1.10 (including) | 1.10 (including) |
Little_cms_color_engine | Littlecms | 1.11 (including) | 1.11 (including) |
Little_cms_color_engine | Littlecms | 1.12 (including) | 1.12 (including) |
Little_cms_color_engine | Littlecms | 1.13 (including) | 1.13 (including) |
Little_cms_color_engine | Littlecms | 1.14 (including) | 1.14 (including) |
Little_cms_color_engine | Littlecms | 1.15 (including) | 1.15 (including) |
Little_cms_color_engine | Littlecms | 1.16 (including) | 1.16 (including) |
Little_cms_color_engine | Littlecms | 1.17 (including) | 1.17 (including) |
Little_cms_color_engine | Littlecms | 1.18 (including) | 1.18 (including) |
Little_cms_color_engine | Littlecms | 1.19 (including) | 1.19 (including) |
Little_cms_color_engine | Littlecms | 2.0 (including) | 2.0 (including) |
Little_cms_color_engine | Littlecms | 2.1 (including) | 2.1 (including) |
Little_cms_color_engine | Littlecms | 2.2 (including) | 2.2 (including) |
Little_cms_color_engine | Littlecms | 2.3 (including) | 2.3 (including) |
Ghostscript | Ubuntu | devel | * |
Ghostscript | Ubuntu | raring | * |
Lcms2 | Ubuntu | precise | * |
Lcms2 | Ubuntu | quantal | * |
Lcms2 | Ubuntu | raring | * |
Lcms2 | Ubuntu | upstream | * |