CVE-2013-4276: Buffer Overflow
Last updated 24 July 2024
Other sources
Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to cause a denial of service (crash) via a crafted (1) ICC color profile to the icctrans utility or (2) TIFF image to the tiffdiff utility.
— Launchpad
Three (two in ColorSpace conversion calculator, one in TIFF compare utility) stack-based buffer overflow flaws were found in the way icctrans / tiffdiff tools of LittleCMS, the color management system, used to process certain ICC color profile / TIFF image format files. Remote attacker could provide a specially-crafted ICC color profile / TIFF image format files that, when opened in color space conversion calculator (icctrans) or TIFF compare utility (tiffdiff) of LittleCMS would lead to that utility crash.
References: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=718682 [2] http://www.openwall.com/lists/oss-security/2013/08/05/2
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4276?
CVE-2013-4276 is classified as a denial of service vulnerability due to multiple stack-based buffer overflows.
How do I fix CVE-2013-4276?
To fix CVE-2013-4276, upgrade to LittleCMS version 2.12~rc1-2 or 2.14-2 in Debian or update to a version of Little CMS Color engine newer than 1.19.
What software is affected by CVE-2013-4276?
CVE-2013-4276 affects LittleCMS versions up to and including 1.19 and specific Debian packages if they are not updated.
What types of files can exploit CVE-2013-4276?
CVE-2013-4276 can be exploited by crafting specific ICC color profiles or TIFF images that trigger the vulnerability.
Is CVE-2013-4276 a remote vulnerability?
Yes, CVE-2013-4276 can be exploited remotely by attackers who send crafted files to vulnerable software.