Vulnerability Description
Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Littlecms | Little Cms Color Engine | 2.0 |
References
- http://www.kb.cert.org/vuls/id/369800Third Party AdvisoryUS Government Resource
- http://www.ubuntu.com/usn/USN-2961-1
- https://github.com/mm2/Little-CMS/commit/fefaaa43c382eee632ea3ad0cfa915335140e1d
- https://penteston.com/OSVDB-105462
- http://www.kb.cert.org/vuls/id/369800Third Party AdvisoryUS Government Resource
- http://www.ubuntu.com/usn/USN-2961-1
- https://github.com/mm2/Little-CMS/commit/fefaaa43c382eee632ea3ad0cfa915335140e1d
- https://penteston.com/OSVDB-105462
FAQ
What is CVE-2013-7455?
CVE-2013-7455 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that tr...
How severe is CVE-2013-7455?
CVE-2013-7455 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2013-7455?
Check the references section above for vendor advisories and patch information. Affected products include: Littlecms Little Cms Color Engine.