Out-of-bounds Write Vulnerability in Little CMS by Little CMS Developers
CVE-2018-11556

7.8HIGH

Key Information:

Vendor

Littlecms

Vendor
CVE Published:
30 May 2018

What is CVE-2018-11556?

Little CMS version 2.9 experiences an out-of-bounds write vulnerability in the cmsPipelineCheckAndRetrieveStages function, found in cmslut.c within liblcms2.a. This issue arises when processing specially crafted TIFF files. While the developers of Little CMS acknowledge this as a vulnerability, it is crucial to note that the issue is only relevant when using a sample program that leverages LIBTIFF, and does not affect the lcms2 library itself. Therefore, users without dependencies on LIBTIFF may not be impacted.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.