CVE-2018-11556

Source
https://cve.org/CVERecord?id=CVE-2018-11556
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11556.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-11556
Published
2018-05-30T04:29:00.457Z
Modified
2026-07-08T14:14:02.374874Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

tificc in Little CMS 2.9 has an out-of-bounds write in the cmsPipelineCheckAndRetreiveStages function in cmslut.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program using LIBTIFF and do not apply to the lcms2 library, lcms2 does not depends on LIBTIFF other than to build sample programs, and the issue cannot be reproduced on the lcms2 library.”

References

Affected packages

Git / github.com/mm2/little-cms

Affected ranges

Type
GIT
Repo
https://github.com/mm2/little-cms
Events
Database specific
{
    "cpe": "cpe:2.3:a:littlecms:little_cms:2.9:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "2.9"
        },
        {
            "last_affected": "2.9"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

2.*
2.9
lcms2.*
lcms2.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11556.json"