First published: Wed Dec 03 2008(Updated: )
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Little CMS Color engine | =1.15 | |
LittleCMS | <=1.16 | |
LittleCMS | =1.08 | |
Little CMS Color engine | =1.12 | |
LittleCMS | =1.14 | |
Little CMS Color engine | =1.13 | |
LittleCMS | =1.15 | |
Little CMS Color engine | =1.11 | |
Little CMS Color engine | =1.08 | |
LittleCMS | =1.07 | |
Little CMS Color engine | =1.10 | |
LittleCMS | =1.13 | |
Little CMS Color engine | =1.09 | |
LittleCMS | =1.12 | |
LittleCMS | =1.11 | |
Little CMS Color engine | <=1.16 | |
Little CMS Color engine | =1.07 | |
LittleCMS | =1.10 | |
LittleCMS | =1.09 | |
Little CMS Color engine | =1.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5317 has been classified as a medium severity vulnerability.
To fix CVE-2008-5317, upgrade to Little CMS Color engine version 1.17 or later.
CVE-2008-5317 is caused by an integer signedness error in the cmsAllocGamma function.
CVE-2008-5317 affects versions of Little CMS Color engine from 1.07 up to and including 1.16.
Yes, CVE-2008-5317 can lead to security breaches by allowing attackers to cause improper memory allocation.