Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 27: 2018-3e9f26489b Critical: lcms2 Heap Overflow Threat

fedora
Calendar Grey October 4, 2018
Dist Fedora Esm H88
Significant lcms2 security patch for Fedora 27 tackling buffer overflow vulnerability. Detailed setup guidelines provided.
Security fix for CVE-2018-16435

Summary

LittleCMS intends to be a small-footprint, speed optimized color management

engine in open source form. LCMS2 is the current version of LCMS, and can be

parallel installed with the original (deprecated) lcms.

Security fix for CVE-2018-16435

* Tue Sep 18 2018 Rex Dieter - 2.8-6

- (branch) CVE-2018-16435 lcms2: heap-based buffer overflow in SetData function in cmsIT8LoadFromFile (#1628969)

[ 1 ] Bug #1628969 - CVE-2018-16435 lcms2: heap-based buffer overflow in SetData function in cmsIT8LoadFromFile

https://bugzilla.redhat.com/show_bug.cgi?id=1628969

su -c 'dnf upgrade --advisory FEDORA-2018-3e9f26489b' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/keys

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 27
Version: 2.8
Release: 6.fc27
Summary: Color Management Engine

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here