CVE-2016-10165: High severity LittleCms Little Cms Color Engine vulnerability
An out-of-bounds read in cmstypes.c in TypeMLURead function was found, leading to heap memory leak triggered by crafted ICC profile.
Upstream patch:
https://github.com/mm2/Little-CMS/commit/5ca71a7bc18b6897ab21d815d15e218e204581e2
CVE request:
http://seclists.org/oss-sec/2016/q3/288
Other sources
The TypeMLURead function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10165?
CVE-2016-10165 is classified as a moderate severity vulnerability that can lead to information disclosure or denial of service.
How do I fix CVE-2016-10165?
To fix CVE-2016-10165, update Little CMS to version 2.8-4 or later if using Ubuntu, or ensure the latest patches are applied for affected distributions.
What are the potential impacts of CVE-2016-10165?
The potential impacts of CVE-2016-10165 include the possibility for remote attackers to read sensitive data or cause a denial of service via a specially crafted ICC profile.
Which systems are affected by CVE-2016-10165?
CVE-2016-10165 affects various versions of Little CMS and specific distributions such as Ubuntu, Debian, and Red Hat Enterprise Linux.
Is there a workaround for CVE-2016-10165?
While updating is the best solution for CVE-2016-10165, a temporary workaround includes implementing network level controls to block untrusted ICC profile processing.