← Back

CVE-2008-5316

nvd nist
Published: Dec 3, 2008Modified: Apr 23, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.

Affected (18)

2 products
Lcms
Little Cms Color Engine
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Littlecms
Up to 1.15
Version 1.07
Version 1.08
Version 1.09
Version 1.10
Version 1.11
Version 1.12
Version 1.13
Version 1.14
Littlecms
Up to 1.15
Version 1.07
Version 1.08
Version 1.09
Version 1.10
Version 1.11
Version 1.12
Version 1.13
Version 1.14

Timeline

No history available yet.