Out-of-bounds Write Vulnerability in Little CMS by Little CMS Developers
CVE-2018-11556
7.8HIGH
What is CVE-2018-11556?
Little CMS version 2.9 experiences an out-of-bounds write vulnerability in the cmsPipelineCheckAndRetrieveStages function, found in cmslut.c within liblcms2.a. This issue arises when processing specially crafted TIFF files. While the developers of Little CMS acknowledge this as a vulnerability, it is crucial to note that the issue is only relevant when using a sample program that leverages LIBTIFF, and does not affect the lcms2 library itself. Therefore, users without dependencies on LIBTIFF may not be impacted.
