First published: Thu Mar 26 2009(Updated: )
cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
sun OpenJDK | =6 | |
LittleCMS | =1.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-0793 is classified as moderate due to its potential to cause denial of service.
To fix CVE-2009-0793, update to the latest version of LittleCMS or OpenJDK that addresses this vulnerability.
CVE-2009-0793 can be exploited by remote attackers through crafted images that trigger a NULL pointer dereference.
CVE-2009-0793 affects LittleCMS version 1.18 and Sun OpenJDK version 6.
Symptoms of a CVE-2009-0793 attack include application crashes due to failed image transformations.