Unrated severityNVD Advisory· Published Mar 23, 2009· Updated Apr 23, 2026
CVE-2009-0723
CVE-2009-0723
Description
Multiple integer overflows in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allow context-dependent attackers to execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.
Affected products
4- cpe:2.3:a:mozilla:firefox:3.1:beta1:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
41- www.securityfocus.com/bid/34185nvdBroken LinkPatchThird Party AdvisoryVDB Entry
- scary.beasts.org/security/CESA-2009-003.htmlnvdExploit
- scarybeastsecurity.blogspot.com/2009/03/littlecms-vulnerabilities.htmlnvdExploit
- lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.htmlnvdThird Party Advisory
- security.gentoo.org/glsa/glsa-200904-19.xmlnvdThird Party Advisory
- slackware.com/security/viewer.phpnvdThird Party Advisory
- www.debian.org/security/2009/dsa-1745nvdThird Party Advisory
- www.debian.org/security/2009/dsa-1769nvdThird Party Advisory
- www.ocert.org/advisories/ocert-2009-003.htmlnvdThird Party Advisory
- www.redhat.com/support/errata/RHSA-2009-0339.htmlnvdBroken LinkVendor Advisory
- www.securityfocus.com/archive/1/502018/100/0/threadednvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/archive/1/502031/100/0/threadednvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/idnvdBroken LinkThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-744-1nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/49326nvdThird Party AdvisoryVDB Entry
- rhn.redhat.com/errata/RHSA-2009-0377.htmlnvdThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-March/msg00794.htmlnvdThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-March/msg00799.htmlnvdThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-March/msg00811.htmlnvdThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-March/msg00851.htmlnvdThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-March/msg00856.htmlnvdThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-March/msg00857.htmlnvdThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-March/msg00921.htmlnvdThird Party Advisory
- secunia.com/advisories/34367nvdBroken Link
- secunia.com/advisories/34382nvdBroken Link
- secunia.com/advisories/34400nvdBroken Link
- secunia.com/advisories/34408nvdBroken Link
- secunia.com/advisories/34418nvdBroken Link
- secunia.com/advisories/34442nvdBroken Link
- secunia.com/advisories/34450nvdBroken Link
- secunia.com/advisories/34454nvdBroken Link
- secunia.com/advisories/34463nvdBroken Link
- secunia.com/advisories/34632nvdBroken Link
- secunia.com/advisories/34675nvdBroken Link
- secunia.com/advisories/34782nvdBroken Link
- www.mandriva.com/security/advisoriesnvdBroken Link
- www.mandriva.com/security/advisoriesnvdBroken Link
- www.mandriva.com/security/advisoriesnvdBroken Link
- www.vupen.com/english/advisories/2009/0775nvdBroken Link
- oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11780nvdTool Signature
News mentions
0No linked articles in our index yet.