10

CVE-2008-5317

Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.

Data is provided by the National Vulnerability Database (NVD)
LittlecmsLcms Version <= 1.16
LittlecmsLcms Version1.07
LittlecmsLcms Version1.08
LittlecmsLcms Version1.09
LittlecmsLcms Version1.10
LittlecmsLcms Version1.11
LittlecmsLcms Version1.12
LittlecmsLcms Version1.13
LittlecmsLcms Version1.14
LittlecmsLcms Version1.15
LittlecmsLittle Cms Color Engine Version <= 1.16
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.95% 0.742
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C