CVE-2013-4276: Littlecms Little CMS Color Engine

Medium severity, CVSS 4.3. EPSS: 4% chance of exploitation in the next 30 days.

Multiple stack-based buffer overflows in LittleCMS (aka lcms or liblcms) 1.19 and earlier allow remote attackers to cause a denial of service (crash) via a crafted (1) ICC color profile to the icctrans utility or (2) TIFF image to the tiffdiff utility.

Affected products

  • Littlecms Little CMS Color Engine: up to and including 1.19; version 1.07 only; version 1.08 only; version 1.09 only; version 1.10 only; version 1.11 only; …

Published 2013-09-28. Last modified 2026-06-16.