CVE Vulnerabilities

CVE-2013-7455

Published: May 07, 2016 | Modified: Apr 12, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.

Affected Software

NameVendorStart VersionEnd Version
Little_cms_color_engineLittlecms2.0 (including)2.0 (including)
Little_cms_color_engineLittlecms2.1 (including)2.1 (including)
Little_cms_color_engineLittlecms2.2 (including)2.2 (including)
Little_cms_color_engineLittlecms2.3 (including)2.3 (including)
Little_cms_color_engineLittlecms2.4 (including)2.4 (including)
Little_cms_color_engineLittlecms2.5 (including)2.5 (including)
Lcms2Ubuntuesm-infra-legacy/trusty*
Lcms2Ubuntutrusty*
Lcms2Ubuntutrusty/esm*
Lcms2Ubuntuupstream*

References