Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23557
HistoryApr 10, 2020 - 12:30 a.m.

Arbitrary Code Execution

2020-04-1000:30:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

0.003 Low

EPSS

Percentile

71.8%

lcms is vulnerable to arbitrary code execution. The vulnerability exists in the way LittleCMS handled color profiles. An attacker could use these flaws to create a specially-crafted image file which could cause a Java application to crash or, possibly, execute arbitrary code when opened.

References