cmsxform.c in LittleCMS (aka lcms or liblcms) 1.18, as used in OpenJDK and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted image that triggers execution of incorrect code for "transformations of monochrome profiles."
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2009-04-09 08:08
Updated : 2023-02-12 17:17
NVD link : CVE-2009-0793
Mitre link : CVE-2009-0793
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
littlecms
- lcms
sun
- openjdk