CVE Vulnerabilities

CVE-2013-4160

Published: Jan 21, 2014 | Modified: Jan 22, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.

Affected Software

Name Vendor Start Version End Version
Little_cms_color_engine Littlecms * 2.4 (including)
Little_cms_color_engine Littlecms 1.07 (including) 1.07 (including)
Little_cms_color_engine Littlecms 1.08 (including) 1.08 (including)
Little_cms_color_engine Littlecms 1.09 (including) 1.09 (including)
Little_cms_color_engine Littlecms 1.10 (including) 1.10 (including)
Little_cms_color_engine Littlecms 1.11 (including) 1.11 (including)
Little_cms_color_engine Littlecms 1.12 (including) 1.12 (including)
Little_cms_color_engine Littlecms 1.13 (including) 1.13 (including)
Little_cms_color_engine Littlecms 1.14 (including) 1.14 (including)
Little_cms_color_engine Littlecms 1.15 (including) 1.15 (including)
Little_cms_color_engine Littlecms 1.16 (including) 1.16 (including)
Little_cms_color_engine Littlecms 1.17 (including) 1.17 (including)
Little_cms_color_engine Littlecms 1.18 (including) 1.18 (including)
Little_cms_color_engine Littlecms 1.19 (including) 1.19 (including)
Little_cms_color_engine Littlecms 2.0 (including) 2.0 (including)
Little_cms_color_engine Littlecms 2.1 (including) 2.1 (including)
Little_cms_color_engine Littlecms 2.2 (including) 2.2 (including)
Little_cms_color_engine Littlecms 2.3 (including) 2.3 (including)

References