moxcms is vulnerable to Out-of-bounds Read
65
Medium Risk
moxcms parses ICC profile LUT and CLUT tags (lutAToB/mAB and lut8/lut16) in its profile reader. The reader read CLUT grid dimensions and input/output channel counts from the profile but did not reject degenerate values, accepting grid dimensions below 2 and using an incorrect OR-based channel-count check. A malformed profile could pass validation and reach CLUT interpolation with incorrect index assumptions, leading to out-of-bounds reads, undefined behavior, or a crash. The fix rejects CLUT grid dimensions less than 2 and corrects the A2B input/output channel validation logic.
You are affected if you are using a version that falls within the vulnerable range and your application parses or transforms untrusted ICC profiles containing LUT/CLUT (mAB/A2B or lut8/lut16) tags.
moxcms is vulnerable to Out-of-bounds Read in versions 0.1.0 - 0.8.1.
Upgrade the moxcms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant