The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Little_cms_color_engine | Littlecms | * | 2.11 (excluding) |
Oracle Java for Red Hat Enterprise Linux 6 | RedHat | java-1.8.0-oracle-1:1.8.0.151-1jpp.1.el6 | * |
Oracle Java for Red Hat Enterprise Linux 6 | RedHat | java-1.7.0-oracle-1:1.7.0.161-1jpp.3.el6 | * |
Oracle Java for Red Hat Enterprise Linux 7 | RedHat | java-1.8.0-oracle-1:1.8.0.151-1jpp.5.el7 | * |
Oracle Java for Red Hat Enterprise Linux 7 | RedHat | java-1.7.0-oracle-1:1.7.0.161-1jpp.4.el7 | * |
Red Hat Enterprise Linux 5 | RedHat | java-1.7.0-openjdk-1:1.7.0.121-2.6.8.1.el5_11 | * |
Red Hat Enterprise Linux 6 | RedHat | java-1.8.0-openjdk-1:1.8.0.111-0.b15.el6_8 | * |
Red Hat Enterprise Linux 6 | RedHat | java-1.7.0-openjdk-1:1.7.0.121-2.6.8.1.el6_8 | * |
Red Hat Enterprise Linux 6 Supplementary | RedHat | java-1.8.0-ibm-1:1.8.0.5.5-1jpp.1.el6_9 | * |
Red Hat Enterprise Linux 6 Supplementary | RedHat | java-1.7.1-ibm-1:1.7.1.4.15-1jpp.3.el6_9 | * |
Red Hat Enterprise Linux 7 | RedHat | java-1.8.0-openjdk-1:1.8.0.111-1.b15.el7_2 | * |
Red Hat Enterprise Linux 7 | RedHat | java-1.7.0-openjdk-1:1.7.0.121-2.6.8.0.el7_3 | * |
Red Hat Enterprise Linux 7 Supplementary | RedHat | java-1.8.0-ibm-1:1.8.0.5.5-1jpp.2.el7 | * |
Red Hat Enterprise Linux 7 Supplementary | RedHat | java-1.7.1-ibm-1:1.7.1.4.15-1jpp.2.el7 | * |
Red Hat Satellite 5.8 | RedHat | java-1.8.0-ibm-1:1.8.0.5.5-1jpp.1.el6_9 | * |
Red Hat Satellite 5.8 ELS | RedHat | java-1.8.0-ibm-1:1.8.0.5.5-1jpp.1.el6_9 | * |
Lcms2 | Ubuntu | artful | * |
Lcms2 | Ubuntu | bionic | * |
Lcms2 | Ubuntu | devel | * |
Lcms2 | Ubuntu | precise | * |
Lcms2 | Ubuntu | trusty | * |
Lcms2 | Ubuntu | upstream | * |
Lcms2 | Ubuntu | vivid/stable-phone-overlay | * |
Lcms2 | Ubuntu | xenial | * |
Lcms2 | Ubuntu | yakkety | * |
Lcms2 | Ubuntu | zesty | * |
Openjdk-7 | Ubuntu | precise | * |
Openjdk-7 | Ubuntu | trusty | * |