Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Fedora 28 lcms2 Heap Overflow Advisory - CVE-2018-16435

fedora
Calendar Grey September 27, 2018
Dist Fedora Esm H88
Urgent security patch for Fedora 28 resolving heap overflow vulnerabilities in lcms2. Implement this update immediately to secure your system.
Security fix for CVE-2018-16435

Summary

LittleCMS intends to be a small-footprint, speed optimized color management

engine in open source form. LCMS2 is the current version of LCMS, and can be

parallel installed with the original (deprecated) lcms.

Security fix for CVE-2018-16435

* Tue Sep 18 2018 Rex Dieter - 2.9-4

- CVE-2018-16435 lcms2: heap-based buffer overflow in SetData function in cmsIT8LoadFromFile (#1628969)

- .spec cosmetics, use %make_build %make_install %ldconfig_scriptlets

* Fri Jul 13 2018 Fedora Release Engineering - 2.9-3

- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild

[ 1 ] Bug #1628969 - CVE-2018-16435 lcms2: heap-based buffer overflow in SetData function in cmsIT8LoadFromFile

https://bugzilla.redhat.com/show_bug.cgi?id=1628969

su -c 'dnf upgrade --advisory FEDORA-2018-1cb4c4a6d8' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 28
Version: 2.9
Release: 4.fc28
Summary: Color Management Engine

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here