Out-of-Bounds Write Vulnerability in Little CMS by Marti Maria
CVE-2018-11555
7.8HIGH
What is CVE-2018-11555?
The vulnerability in Little CMS affects version 2.9, specifically in the PrecalculatedXFORM function found in cmsxform.c within liblcms2.a. This vulnerability can be triggered by a specifically crafted TIFF file leading to an out-of-bounds write issue. While Little CMS developers do not consider it a vulnerability in their library itself—given that the problem arises in a sample program utilizing LIBTIFF—it's essential for users to be aware of potential security implications when handling TIFF files.
