CVE-2009-0733

Advisory lineage Upstream: 0 Downstream: 4
Modified
Published: 23 Mar 2009, 14:00
Last modified:07 Aug 2024, 04:48

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.3 HIGH
v2.0 (nvd)
EPSS Score
1.86% LOW
2% probability +0.26%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

23 Mar 2009, 14:00
Published
Vulnerability first disclosed
07 Aug 2024, 04:48
Last Modified
Vulnerability information updated

Description

Multiple stack-based buffer overflows in the ReadSetOfCurves function in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file associated with a large integer value for the (1) input or (2) output channel, related to the ReadLUT_A2B and ReadLUT_B2A functions.

CVSS Metrics

  • v2.0HIGHScore: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 1.86% Percentile: 83%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • gimpgimp

    < 2.9.2

  • littlecmslittle_cms

    ≤ 1.17

  • mozillafirefox

    3.1:beta1

  • sunopenjdk

    ≤ 7

References (41)