Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

Project Subscriptions

Vendors Products
Littlecms Subscribe
Little Cms Subscribe
Mozilla Subscribe
Firefox Subscribe
Enterprise Linux Subscribe
Openjdk Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-1745-1 New lcms packages fix arbitrary code execution
Debian DSA Debian DSA DSA-1745-2 New lcms packages fix regression
Debian DSA Debian DSA DSA-1769-1 New openjdk-6 packages fix arbitrary code execution
EUVD EUVD EUVD-2009-0723 Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
Ubuntu USN Ubuntu USN USN-744-1 LittleCMS vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html cve-icon cve-icon
http://scary.beasts.org/security/CESA-2009-003.html cve-icon cve-icon
http://scarybeastsecurity.blogspot.com/2009/03/littlecms-vulnerabilities.html cve-icon cve-icon
http://secunia.com/advisories/34367 cve-icon cve-icon
http://secunia.com/advisories/34382 cve-icon cve-icon
http://secunia.com/advisories/34400 cve-icon cve-icon
http://secunia.com/advisories/34408 cve-icon cve-icon
http://secunia.com/advisories/34418 cve-icon cve-icon
http://secunia.com/advisories/34442 cve-icon cve-icon
http://secunia.com/advisories/34450 cve-icon cve-icon
http://secunia.com/advisories/34454 cve-icon cve-icon
http://secunia.com/advisories/34463 cve-icon cve-icon
http://secunia.com/advisories/34632 cve-icon cve-icon
http://secunia.com/advisories/34675 cve-icon cve-icon
http://secunia.com/advisories/34782 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-200904-19.xml cve-icon cve-icon
http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.487438 cve-icon cve-icon
http://www.debian.org/security/2009/dsa-1745 cve-icon cve-icon
http://www.debian.org/security/2009/dsa-1769 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2009:121 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2009:137 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2009:162 cve-icon cve-icon
http://www.ocert.org/advisories/ocert-2009-003.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2009-0339.html cve-icon cve-icon
http://www.securityfocus.com/archive/1/502018/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/archive/1/502031/100/0/threaded cve-icon cve-icon
http://www.securityfocus.com/bid/34185 cve-icon cve-icon
http://www.securitytracker.com/id?1021869 cve-icon cve-icon
http://www.ubuntu.com/usn/USN-744-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2009/0775 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=487508 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/49326 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2009-0723 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11780 cve-icon cve-icon
https://rhn.redhat.com/errata/RHSA-2009-0377.html cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2009-0723 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00794.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00799.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00811.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00851.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00856.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00857.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00921.html cve-icon cve-icon
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-07T04:48:51.612Z

Reserved: 2009-02-24T00:00:00.000Z

Link: CVE-2009-0723

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2009-03-23T14:19:12.500

Modified: 2025-04-09T00:30:58.490

Link: CVE-2009-0723

cve-icon Redhat

Severity : Moderate

Publid Date: 2009-03-19T00:00:00Z

Links: CVE-2009-0723 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses