CVE-2013-4276

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
28/09/2013
Last modified:
11/04/2025

Description

Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to cause a denial of service (crash) via a crafted (1) ICC color profile to the icctrans utility or (2) TIFF image to the tiffdiff utility.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:littlecms:little_cms_color_engine:*:*:*:*:*:*:*:* 1.19 (including)
cpe:2.3:a:littlecms:little_cms_color_engine:1.07:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:1.08:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:1.09:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:1.10:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:1.11:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:1.12:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:1.13:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:1.14:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:1.15:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:1.16:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:1.17:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:1.18:*:*:*:*:*:*:*