| CVE |  | CVE-2009-0581 |
| Status |  | UNKNOWN |
| Description |  | Memory leak in LittleCMS (aka lcms or liblcms) before 1.18beta2, as used in Firefox 3.1beta, OpenJDK, and GIMP, allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted image file. |
| Severity |  | Medium |
| CVSS score |  | 4,3 |
| CVSS vector |  | (AV:N/AC:M/Au:N/C:N/I:N/A:P) |
| Phase |  | ASSIGNED (21.08.2010) |
| NVD: |  | http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0581 |
| References |  | BID : 34185 |
| |  | BUGTRAQ : 20090320 [oCERT-2009-003] LittleCMS integer errors |
| |  | BUGTRAQ : 20090320 LittleCMS vulnerabilities (OpenJDK, Firefox, GIMP, etc. impacted) |
| |  | CONFIRM : https://bugzilla.redhat.com/show_bug.cgi?id=487509 |
| |  | DEBIAN : DSA-1745 |
| |  | DEBIAN : DSA-1769 |
| |  | FEDORA : FEDORA-2009-2903 |
| |  | FEDORA : FEDORA-2009-2910 |
| |  | FEDORA : FEDORA-2009-2928 |
| |  | FEDORA : FEDORA-2009-2970 |
| |  | FEDORA : FEDORA-2009-2982 |
| |  | FEDORA : FEDORA-2009-2983 |
| |  | FEDORA : FEDORA-2009-3034 |
| |  | GENTOO : GLSA-200904-19 |
| |  | MANDRIVA : MDVSA-2009:121 |
| |  | MANDRIVA : MDVSA-2009:137 |
| |  | MANDRIVA : MDVSA-2009:162 |
| |  | MISC : http://scary.beasts.org/security/CESA-2009-003.html |
| |  | MISC : http://scarybeastsecurity.blogspot.com/2009/03/lit... |
| |  | MISC : http://www.ocert.org/advisories/ocert-2009-003.html |
| |  | OVAL : oval:org.mitre.oval:def:10023 |
| |  | REDHAT : RHSA-2009:0339 |
| |  | REDHAT : RHSA-2009:0377 |
| |  | SECTRACK : 1021870 |
| |  | SECUNIA : 34367 |
| |  | SECUNIA : 34382 |
| |  | SECUNIA : 34400 |
| |  | SECUNIA : 34408 |
| |  | SECUNIA : 34418 |
| |  | SECUNIA : 34442 |
| |  | SECUNIA : 34450 |
| |  | SECUNIA : 34454 |
| |  | SECUNIA : 34463 |
| |  | SECUNIA : 34632 |
| |  | SECUNIA : 34675 |
| |  | SECUNIA : 34782 |
| |  | SLACKWARE : SSA:2009-083-01 |
| |  | SUSE : SUSE-SR:2009:007 |
| |  | UBUNTU : USN-744-1 |
| |  | VUPEN : ADV-2009-0775 |
| |  | XF : littlecms-unspecified-dos(49328) |
| SecurityVulns: |  | Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) |
| |  | lcms multiple security vulnerabilities |