CVE Vulnerabilities

CVE-2013-4160

Published: Jan 21, 2014 | Modified: Jan 22, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
4.6 MODERATE
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.

Affected Software

Name Vendor Start Version End Version
Little_cms_color_engine Littlecms * 2.4 (including)
Little_cms_color_engine Littlecms 1.07 (including) 1.07 (including)
Little_cms_color_engine Littlecms 1.08 (including) 1.08 (including)
Little_cms_color_engine Littlecms 1.09 (including) 1.09 (including)
Little_cms_color_engine Littlecms 1.10 (including) 1.10 (including)
Little_cms_color_engine Littlecms 1.11 (including) 1.11 (including)
Little_cms_color_engine Littlecms 1.12 (including) 1.12 (including)
Little_cms_color_engine Littlecms 1.13 (including) 1.13 (including)
Little_cms_color_engine Littlecms 1.14 (including) 1.14 (including)
Little_cms_color_engine Littlecms 1.15 (including) 1.15 (including)
Little_cms_color_engine Littlecms 1.16 (including) 1.16 (including)
Little_cms_color_engine Littlecms 1.17 (including) 1.17 (including)
Little_cms_color_engine Littlecms 1.18 (including) 1.18 (including)
Little_cms_color_engine Littlecms 1.19 (including) 1.19 (including)
Little_cms_color_engine Littlecms 2.0 (including) 2.0 (including)
Little_cms_color_engine Littlecms 2.1 (including) 2.1 (including)
Little_cms_color_engine Littlecms 2.2 (including) 2.2 (including)
Little_cms_color_engine Littlecms 2.3 (including) 2.3 (including)
Ghostscript Ubuntu devel *
Ghostscript Ubuntu raring *
Lcms2 Ubuntu precise *
Lcms2 Ubuntu quantal *
Lcms2 Ubuntu raring *
Lcms2 Ubuntu upstream *

References