Stack-based Buffer Overflow in LittleCMS Affects Multiple Products
CVE-2009-0733

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
23 March 2009

What is CVE-2009-0733?

LittleCMS, a color management system, contains multiple stack-based buffer overflow vulnerabilities within the ReadSetOfCurves function. These flaws, present in versions prior to 1.18beta2, can be exploited by context-dependent attackers using specially-crafted image files to trigger arbitrary code execution. The issue stems from an improper handling of large integer values during input or output channel processing, specifically relating to ReadLUT_A2B and ReadLUT_B2A functions. Affected products include Firefox, OpenJDK, and GIMP, making this a critical concern for users relying on these applications.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.