CVE-2007-2741: Buffer Overflow
Published May 17, 2007
·Updated
Stack-based buffer overflow in Little CMS (lcms) before 1.15 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ICC profile in a JPG file.
Affected Software
8 affected components
LittleCms lcms<=1.14
LittleCms lcms=1.07
LittleCms lcms=1.08
LittleCms lcms=1.09
LittleCms lcms=1.10
LittleCms lcms=1.11
LittleCms lcms=1.12
LittleCms lcms=1.13
Remediation
Patch Available
Patch Available
Event History
May 17, 2007
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2741?
CVE-2007-2741 is classified as a critical vulnerability due to the potential for remote code execution and denial of service.
2
How do I fix CVE-2007-2741?
To fix CVE-2007-2741, upgrade Little CMS to version 1.15 or later.
3
Who is affected by CVE-2007-2741?
CVE-2007-2741 affects all versions of Little CMS prior to 1.15.
4
What type of attack does CVE-2007-2741 enable?
CVE-2007-2741 enables remote attackers to execute arbitrary code or crash the application.
5
What causes CVE-2007-2741?
CVE-2007-2741 is caused by a stack-based buffer overflow when processing crafted ICC profiles in JPG files.