Security Advisory

CVE-2018-16435

5.5
MEDIUM

Vulnerability Description

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.
Published Date September 4, 2018
Official Source NIST NVD Advisory