CVE-2008-5317: Critical severity little cms color engine vulnerability
Published Dec 3, 2008
·Updated
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.
Affected Software
20 affected components
LittleCms Little Cms Color Engine=1.15
LittleCms lcms<=1.16
LittleCms lcms=1.08
LittleCms Little Cms Color Engine=1.12
LittleCms lcms=1.14
LittleCms Little Cms Color Engine=1.13
LittleCms lcms=1.15
LittleCms Little Cms Color Engine=1.11
LittleCms Little Cms Color Engine=1.08
LittleCms lcms=1.07
LittleCms Little Cms Color Engine=1.10
LittleCms lcms=1.13
LittleCms Little Cms Color Engine=1.09
LittleCms lcms=1.12
LittleCms lcms=1.11
LittleCms Little Cms Color Engine<=1.16
LittleCms Little Cms Color Engine=1.07
LittleCms lcms=1.10
LittleCms lcms=1.09
LittleCms Little Cms Color Engine=1.14
Remediation
Event History
Dec 3, 2008
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-5317?
CVE-2008-5317 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2008-5317?
To fix CVE-2008-5317, upgrade to Little CMS Color engine version 1.17 or later.
3
What causes CVE-2008-5317?
CVE-2008-5317 is caused by an integer signedness error in the cmsAllocGamma function.
4
Which versions of Little CMS Color engine are affected by CVE-2008-5317?
CVE-2008-5317 affects versions of Little CMS Color engine from 1.07 up to and including 1.16.
5
Can CVE-2008-5317 lead to security breaches?
Yes, CVE-2008-5317 can lead to security breaches by allowing attackers to cause improper memory allocation.