Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7443
HistorySep 07, 2018 - 5:40 a.m.

Denial Of Service (DoS)

2018-09-0705:40:49
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

0.002 Low

EPSS

Percentile

53.4%

liblcms2.so is vulnerable to denial of service. The vulnerability exists in the AllocateDataSet function of cmscgats.c because of not limiting the size of the Data from integer multiplication, leading to an attack if a malicious IT8 calibration file is passed to the second argument to cmsIT8LoadFromFile.