CVE-2016-10165

Advisory lineage Upstream: 0 Downstream: 22
Modified
Published: 03 Feb 2017, 19:00
Last modified:06 Aug 2024, 03:14

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
7.1 HIGH
v3.1 (nvd)
EPSS Score
0.56% LOW
1% probability +0.04%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Feb 2017, 19:00
Published
Vulnerability first disclosed
06 Aug 2024, 03:14
Last Modified
Vulnerability information updated

Description

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

CVSS Metrics

  • v3.1HIGHScore: 7.1CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
  • v2.0MEDIUMScore: 5.8AV:N/AC:M/Au:N/C:P/I:N/A:P

EPSS Trends

Current EPSS score: 0.56% Percentile: 68%

Techniques & Countermeasures

  • CWE-125Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04 | 16.04 | 18.04

  • debiandebian_linux

    8.0

  • littlecmslittle_cms_color_engine

    < 2.11

  • netappactive_iq_unified_manager

    ≥ 7.3 | ≥ 9.5

  • netappe-series_santricity_management

    na

  • netappe-series_santricity_os_controller

    11.0 | 11.0.0 | 11.20 | 11.25 | 11.30 | 11.30.5r3 | 11.40 | 11.40.3r2 | 11.40.5 | 11.50.1 | 11.50.2 | 11.50.2:p1 | 11.60 | 11.60.0 | 11.60.1 | 11.60.3 | 11.70.1 | 11.70.2

  • netapponcommand_balance

    na

  • netapponcommand_insight

    na

  • netapponcommand_performance_manager

    na

  • netapponcommand_shift

    na

  • netapponcommand_unified_manager

    na | 7.1

  • opensuseleap

    42.1

  • redhatenterprise_linux_desktop

    5.0 | 6.0 | 7.0

  • redhatenterprise_linux_server

    5.0 | 6.0 | 7.0

  • redhatenterprise_linux_server_aus

    7.3 | 7.4 | 7.6 | 7.7

  • redhatenterprise_linux_server_eus

    7.3 | 7.4 | 7.5 | 7.6 | 7.7

  • redhatenterprise_linux_server_tus

    7.3 | 7.6 | 7.7

  • redhatenterprise_linux_workstation

    5.0 | 6.0 | 7.0

  • redhatsatellite

    5.8

References (19)