CVE-2009-0793: Input Validation
cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0793?
The severity of CVE-2009-0793 is classified as moderate due to its potential to cause denial of service.
How do I fix CVE-2009-0793?
To fix CVE-2009-0793, update to the latest version of LittleCMS or OpenJDK that addresses this vulnerability.
What types of attacks can exploit CVE-2009-0793?
CVE-2009-0793 can be exploited by remote attackers through crafted images that trigger a NULL pointer dereference.
Which software is affected by CVE-2009-0793?
CVE-2009-0793 affects LittleCMS version 1.18 and Sun OpenJDK version 6.
What are the symptoms of a CVE-2009-0793 attack?
Symptoms of a CVE-2009-0793 attack include application crashes due to failed image transformations.