Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 20: Critical Buffer Overflow in lcms CVE-2013-4276 Fix

fedora
Calendar Grey April 23, 2015
Dist Fedora Esm H88
Fedora 20 has released a crucial update for its color management system, fixing a critical vulnerability CVE-2013-4276 and addressing performance issues from uninitialized variables
* apply patch for CVE-2013-4276 * apply patch for "Use of uninitialized values on 64 bit machines."

Summary

LittleCMS intends to be a small-footprint, speed optimized color management

engine in open source form.

Update Information:

* apply patch for CVE-2013-4276 * apply patch for "Use of uninitialized values on 64 bit machines."


Change Log

* Sun Aug 17 2014 Fedora Release Engineering - 1.19-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild * Sat Jun 7 2014 Fedora Release Engineering - 1.19-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Mon Dec 9 2013 Michael Schwendt - 1.19-11 - apply patch for CVE-2013-4276 (#991757, #992979) - apply patch for "Use of uninitialized values on 64 bit machines." (#1003950) - add %_isa in -libs base package deps - drop %defattr usage * Wed Sep 4 2013 Nils Philippsen - fix bogus dates in changelog

References


[ 1 ] Bug #992975 - CVE-2013-4276 lcms: Stack-based buffer overflows in ColorSpace conversion calculator and TIFF compare utility https://bugzilla.redhat.com/show_bug.cgi?id=992975

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update lcms' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: lcms
Product: Fedora 20
Version: 1.19
Release: 13.fc20
Summary: Color Management System

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here