Description
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
Published: 2017-02-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-803-1 lcms2 security update
Debian DSA Debian DSA DSA-3774-1 lcms2 security update
Ubuntu USN Ubuntu USN USN-3770-1 Little CMS vulnerabilities
Ubuntu USN Ubuntu USN USN-3770-2 Little CMS vulnerabilities
History

No history.

Subscriptions

Canonical Ubuntu Linux
Debian Debian Linux
Littlecms Little Cms Color Engine
Netapp Active Iq Unified Manager E-series Santricity Management E-series Santricity Os Controller Oncommand Balance Oncommand Insight Oncommand Performance Manager Oncommand Shift Oncommand Unified Manager
Opensuse Leap
Redhat Enterprise Linux Enterprise Linux Desktop Enterprise Linux Server Enterprise Linux Server Aus Enterprise Linux Server Eus Enterprise Linux Server Tus Enterprise Linux Workstation Network Satellite Rhel Extras Rhel Extras Oracle Java Satellite
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-06T03:14:42.619Z

Reserved: 2017-01-25T00:00:00.000Z

Link: CVE-2016-10165

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-02-03T19:59:00.177

Modified: 2025-04-20T01:37:25.860

Link: CVE-2016-10165

cve-icon Redhat

Severity : Moderate

Publid Date: 2016-08-15T00:00:00Z

Links: CVE-2016-10165 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses