Lucene search

K
nvd[email protected]NVD:CVE-2008-5316
HistoryDec 03, 2008 - 5:30 p.m.

CVE-2008-5316

2008-12-0317:30:00
CWE-119
web.nvd.nist.gov

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.3 Medium

AI Score

Confidence

Low

0.044 Low

EPSS

Percentile

92.4%

Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of “the input file,” a different vulnerability than CVE-2007-2741.

Affected configurations

NVD
Node
littlecmslcmsRange1.15
OR
littlecmslcmsMatch1.07
OR
littlecmslcmsMatch1.08
OR
littlecmslcmsMatch1.09
OR
littlecmslcmsMatch1.10
OR
littlecmslcmsMatch1.11
OR
littlecmslcmsMatch1.12
OR
littlecmslcmsMatch1.13
OR
littlecmslcmsMatch1.14
OR
littlecmslittle_cms_color_engineRange1.15
OR
littlecmslittle_cms_color_engineMatch1.07
OR
littlecmslittle_cms_color_engineMatch1.08
OR
littlecmslittle_cms_color_engineMatch1.09
OR
littlecmslittle_cms_color_engineMatch1.10
OR
littlecmslittle_cms_color_engineMatch1.11
OR
littlecmslittle_cms_color_engineMatch1.12
OR
littlecmslittle_cms_color_engineMatch1.13
OR
littlecmslittle_cms_color_engineMatch1.14

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.3 Medium

AI Score

Confidence

Low

0.044 Low

EPSS

Percentile

92.4%