CVE-2013-7455
Last modified
CVE-2013-7455 is a vulnerability of currently unknown severity. Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.. EPSS estimates a 6.23% chance of exploitation in the next 30 days.
Description
Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Littlecms | Little Cms Color Engine | 2.0 |
| Littlecms | Little Cms Color Engine | 2.1 |
| Littlecms | Little Cms Color Engine | 2.2 |
| Littlecms | Little Cms Color Engine | 2.3 |
| Littlecms | Little Cms Color Engine | 2.4 |
| Littlecms | Little Cms Color Engine | 2.5 |
References
- http://www.kb.cert.org/vuls/id/369800Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/369800Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-7455?
How severe is CVE-2013-7455?
How do I fix CVE-2013-7455?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-7449The ssl_do_connect function in common/server.c in HexChat be…
- CVE-2013-7450Pulp before 2.3.0 uses the same the same certificate authori…
- CVE-2013-7451The validator module before 1.1.0 for Node.js allows remote …
- CVE-2013-7452The validator module before 1.1.0 for Node.js allows remote …
- CVE-2013-7453The validator module before 1.1.0 for Node.js allows remote …
- CVE-2013-7454The validator module before 1.1.0 for Node.js allows remote …
- CVE-2013-7456gd_interpolation.c in the GD Graphics Library (aka libgd) be…
- CVE-2013-7457Unspecified vulnerability in the Qualcomm components in Andr…
- CVE-2013-7458linenoise, as used in Redis before 3.2.3, uses world-readabl…
- CVE-2013-7459Heap-based buffer overflow in the ALGnew function in block_t…
- CVE-2013-7460A write protection and execution bypass vulnerability in McA…
- CVE-2013-7461A write protection and execution bypass vulnerability in McA…
Are you affected by CVE-2013-7455?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
