Unrated severityNVD Advisory· Published Dec 3, 2008· Updated Apr 23, 2026
CVE-2008-5317
CVE-2008-5317
Description
Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.
Affected products
20cpe:2.3:a:littlecms:lcms:1.14:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:littlecms:lcms:1.14:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:lcms:1.15:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:lcms:*:*:*:*:*:*:*:*range: <=1.16
- cpe:2.3:a:littlecms:lcms:1.07:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:lcms:1.08:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:lcms:1.09:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:lcms:1.10:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:lcms:1.11:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:lcms:1.12:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:lcms:1.13:*:*:*:*:*:*:*
cpe:2.3:a:littlecms:little_cms_color_engine:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:littlecms:little_cms_color_engine:*:*:*:*:*:*:*:*range: <=1.16
- cpe:2.3:a:littlecms:little_cms_color_engine:1.07:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:little_cms_color_engine:1.08:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:little_cms_color_engine:1.09:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:little_cms_color_engine:1.10:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:little_cms_color_engine:1.11:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:little_cms_color_engine:1.12:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:little_cms_color_engine:1.13:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:little_cms_color_engine:1.14:*:*:*:*:*:*:*
- cpe:2.3:a:littlecms:little_cms_color_engine:1.15:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- lcms.cvs.sourceforge.net/viewvc/lcms/lcms/src/cmsgamma.cnvdPatch
- secunia.com/advisories/33066nvd
- secunia.com/advisories/33219nvd
- www.debian.org/security/2008/dsa-1684nvd
- www.openwall.com/lists/oss-security/2008/11/28/3nvd
- www.redhat.com/support/errata/RHSA-2009-0011.htmlnvd
- www.securityfocus.com/bid/32708nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/47120nvd
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10685nvd
- usn.ubuntu.com/693-1/nvd
News mentions
0No linked articles in our index yet.