CVE-2018-11555
Last modified
CVE-2018-11555 is a vulnerability of currently unknown severity. tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program using LIBTIFF and do not apply to the lcms2 library, lcms2 does not depends on LIBTIFF other than to build sample programs, and the issue cannot be reproduced on the lcms2 library.”. EPSS estimates a 1.07% chance of exploitation in the next 30 days.
Description
tificc in Little CMS 2.9 has an out-of-bounds write in the PrecalculatedXFORM function in cmsxform.c in liblcms2.a via a crafted TIFF file. NOTE: Little CMS developers do consider this a vulnerability because the issue is based on an sample program using LIBTIFF and do not apply to the lcms2 library, lcms2 does not depends on LIBTIFF other than to build sample programs, and the issue cannot be reproduced on the lcms2 library.”
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Littlecms | Little Cms | 2.9 |
References
- https://github.com/mm2/Little-CMS/issues/167Third Party Advisory
- https://github.com/xiaoqx/pocs/tree/master/cmsThird Party Advisory
- https://github.com/mm2/Little-CMS/issues/167Third Party Advisory
- https://github.com/xiaoqx/pocs/tree/master/cmsThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-11555?
How severe is CVE-2018-11555?
How do I fix CVE-2018-11555?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-1155In SecurityCenter versions prior to 5.7.0, a cross-site scri…
- CVE-2018-11550Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-11551AXON PBX 2.02 contains a DLL hijacking vulnerability that co…
- CVE-2018-11552There is a reflected XSS vulnerability in AXON PBX 2.02 via …
- CVE-2018-11553SGIN.CN xiangyun platform V9.4.10 has XSS via the login_url …
- CVE-2018-11554The forgotten-password feature in index.php/member/reset/res…
- CVE-2018-11556tificc in Little CMS 2.9 has an out-of-bounds write in the c…
- CVE-2018-11557YIBAN Easy class education platform 2.0 has XSS via the arti…
- CVE-2018-11558DomainMod 4.10.0 has Stored XSS in the "/settings/profile/in…
- CVE-2018-11559DomainMod 4.10.0 has Stored XSS in the "/settings/profile/in…
- CVE-2018-1156Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to …
- CVE-2018-11560The webService binary on Insteon HD IP Camera White 2864-222…9.8
Are you affected by CVE-2018-11555?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
