{"id":"UBUNTU-CVE-2012-1616","details":"Use-after-free vulnerability in icclib before 2.13, as used by Argyll CMS before 1.4 and possibly other programs, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted ICC profile file.","modified":"2025-07-16T08:10:33.180643Z","published":"2012-06-21T15:55:00Z","withdrawn":"2025-07-18T16:42:45Z","upstream":["CVE-2012-1616"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2012-1616"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=809697"},{"type":"REPORT","url":"http://xforce.iss.net/xforce/xfdb/75162"},{"type":"REPORT","url":"http://www.argyllcms.com/icc_readme.html"},{"type":"REPORT","url":"http://security.gentoo.org/glsa/glsa-201206-04.xml"},{"type":"REPORT","url":"http://secunia.com/advisories/49602"},{"type":"REPORT","url":"http://secunia.com/advisories/48921"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2012-1616"}],"affected":[{"package":{"name":"argyll","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/argyll@1.5.1-5ubuntu1?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.1-5ubuntu1"}]}],"versions":["1.4.0-8ubuntu5"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"1.5.1-5ubuntu1","binary_name":"argyll"},{"binary_name":"argyll-dbg","binary_version":"1.5.1-5ubuntu1"},{"binary_name":"icc-utils","binary_version":"1.5.1-5ubuntu1"},{"binary_name":"libicc-dev","binary_version":"2.12+argyll1.5.1-5ubuntu1"},{"binary_name":"libicc2","binary_version":"2.12+argyll1.5.1-5ubuntu1"},{"binary_name":"libimdi-dev","binary_version":"1.5.1-5ubuntu1"},{"binary_name":"libimdi0","binary_version":"1.5.1-5ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2012/UBUNTU-CVE-2012-1616.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}