The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
References
Information
Published : 2017-02-03 11:59
Updated : 2018-10-30 09:27
NVD link : CVE-2016-10165
Mitre link : CVE-2016-10165
JSON object : View
CWE
CWE-125
Out-of-bounds Read
Products Affected
debian
- debian_linux
littlecms
- little_cms_color_engine
opensuse
- leap