--------------------------------------------------------------------------------Fedora Update Notification
FEDORA-2009-3430
2009-04-09 15:24:29
--------------------------------------------------------------------------------Name        : argyllcms
Product     : Fedora 9
Version     : 1.0.3
Release     : 4.fc9
URL         : http://www.argyllcms.com/
Summary     : ICC compatible color management system
Description :
The Argyll color management system supports accurate ICC profile creation for
scanners, CMYK printers, film recorders and calibration and profiling of
displays.

Spectral sample data is supported, allowing a selection of illuminants observer
types, and paper fluorescent whitener additive compensation. Profiles can also
incorporate source specific gamut mappings for perceptual and saturation
intents. Gamut mapping and profile linking uses the CIECAM02 appearance model,
a unique gamut mapping algorithm, and a wide selection of rendering intents. It
also includes code for the fastest portable 8 bit raster color conversion
engine available anywhere, as well as support for fast, fully accurate 16 bit
conversion. Device color gamuts can also be viewed and compared using a VRML
viewer.

--------------------------------------------------------------------------------Update Information:

Multiple integer overflows and multiple insufficient upper-bounds checks on
certain variable sizes were originally discovered in the Ghostscript's
International Color Consortium Format Library (icclib). It was found,  the
original patch, addressing this issue was incomplete.
--------------------------------------------------------------------------------ChangeLog:

* Wed Apr  8 2009 Jon Ciesla  - 1.0.3-4
- Patch for ICC library CVE-2009-0792.
* Mon Mar 23 2009 Jon Ciesla  - 1.0.3-3
- Patch for ICC library CVE-2009-{0583, 0584} by Tim Waugh.
* Mon Feb 23 2009 Fedora Release Engineering  - 1.0.3-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
* Wed Sep  3 2008 Nicolas Mailhot 
- 1.0.3-1
⌨ Bugfix release
* Mon Sep  1 2008 Nicolas Mailhot 
- 1.0.2-1
ᾢ Bugfix release
* Sun Jul 27 2008 Nicolas Mailhot 
- 1.0.1-1
☻ Lots of workarounds dropped — Argyll continues progressing towards “normal
  package” state
☺ No more jam hell ☡, autotooling patch by Alastair M. Robinson ♥♥♥
♿ New workaround added for private libusb check ⚔ We build againt system
  libusb, and will fix ⚕ any problem people care to report
⁜ Re-applied some patches still not merged upstream, including the legal ⚖ one
⚙ It builds, what can go wrong⁉
⁂ Changed Huey policy file. Huey users, please test
--------------------------------------------------------------------------------References:

  [ 1 ] Bug #491853 - CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583
        https://bugzilla.redhat.com/show_bug.cgi?id=491853
--------------------------------------------------------------------------------This update can be installed with the "yum" update program.  Use 
su -c 'yum update argyllcms' at the command line.
For more information, refer to "Managing Software with yum",
available at .

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------_______________________________________________
Fedora-package-announce mailing list
Fedora-package-announce@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-package-announce

Fedora 9 Update: argyllcms-1.0.3-4.fc9

April 9, 2009
Multiple integer overflows and multiple insufficient upper-bounds checks on certain variable sizes were originally discovered in the Ghostscript's International Color Consortium ...

Summary

The Argyll color management system supports accurate ICC profile creation for

scanners, CMYK printers, film recorders and calibration and profiling of

displays.

Spectral sample data is supported, allowing a selection of illuminants observer

types, and paper fluorescent whitener additive compensation. Profiles can also

incorporate source specific gamut mappings for perceptual and saturation

intents. Gamut mapping and profile linking uses the CIECAM02 appearance model,

a unique gamut mapping algorithm, and a wide selection of rendering intents. It

also includes code for the fastest portable 8 bit raster color conversion

engine available anywhere, as well as support for fast, fully accurate 16 bit

conversion. Device color gamuts can also be viewed and compared using a VRML

viewer.

Multiple integer overflows and multiple insufficient upper-bounds checks on

certain variable sizes were originally discovered in the Ghostscript's

International Color Consortium Format Library (icclib). It was found, the

original patch, addressing this issue was incomplete.

* Wed Apr 8 2009 Jon Ciesla - 1.0.3-4

- Patch for ICC library CVE-2009-0792.

* Mon Mar 23 2009 Jon Ciesla - 1.0.3-3

- Patch for ICC library CVE-2009-{0583, 0584} by Tim Waugh.

* Mon Feb 23 2009 Fedora Release Engineering - 1.0.3-2

- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild

* Wed Sep 3 2008 Nicolas Mailhot

- 1.0.3-1

⌨ Bugfix release

* Mon Sep 1 2008 Nicolas Mailhot

- 1.0.2-1

ᾢ Bugfix release

* Sun Jul 27 2008 Nicolas Mailhot

- 1.0.1-1

☻ Lots of workarounds dropped — Argyll continues progressing towards “normal

package” state

☺ No more jam hell ☡, autotooling patch by Alastair M. Robinson ♥♥♥

♿ New workaround added for private libusb check ⚔ We build againt system

libusb, and will fix ⚕ any problem people care to report

⁜ Re-applied some patches still not merged upstream, including the legal ⚖ one

⚙ It builds, what can go wrong⁉

⁂ Changed Huey policy file. Huey users, please test

[ 1 ] Bug #491853 - CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583

https://bugzilla.redhat.com/show_bug.cgi?id=491853

su -c 'yum update argyllcms' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

http://www.redhat.com/mailman/listinfo/fedora-package-announce

FEDORA-2009-3430 2009-04-09 15:24:29 Product : Fedora 9 Version : 1.0.3 Release : 4.fc9 URL : http://www.argyllcms.com/ Summary : ICC compatible color management system Description : The Argyll color management system supports accurate ICC profile creation for scanners, CMYK printers, film recorders and calibration and profiling of displays. Spectral sample data is supported, allowing a selection of illuminants observer types, and paper fluorescent whitener additive compensation. Profiles can also incorporate source specific gamut mappings for perceptual and saturation intents. Gamut mapping and profile linking uses the CIECAM02 appearance model, a unique gamut mapping algorithm, and a wide selection of rendering intents. It also includes code for the fastest portable 8 bit raster color conversion engine available anywhere, as well as support for fast, fully accurate 16 bit conversion. Device color gamuts can also be viewed and compared using a VRML viewer. Multiple integer overflows and multiple insufficient upper-bounds checks on certain variable sizes were originally discovered in the Ghostscript's International Color Consortium Format Library (icclib). It was found, the original patch, addressing this issue was incomplete. * Wed Apr 8 2009 Jon Ciesla - 1.0.3-4 - Patch for ICC library CVE-2009-0792. * Mon Mar 23 2009 Jon Ciesla - 1.0.3-3 - Patch for ICC library CVE-2009-{0583, 0584} by Tim Waugh. * Mon Feb 23 2009 Fedora Release Engineering - 1.0.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Wed Sep 3 2008 Nicolas Mailhot - 1.0.3-1 ⌨ Bugfix release * Mon Sep 1 2008 Nicolas Mailhot - 1.0.2-1 ᾢ Bugfix release * Sun Jul 27 2008 Nicolas Mailhot - 1.0.1-1 ☻ Lots of workarounds dropped — Argyll continues progressing towards “normal package” state ☺ No more jam hell ☡, autotooling patch by Alastair M. Robinson ♥♥♥ ♿ New workaround added for private libusb check ⚔ We build againt system libusb, and will fix ⚕ any problem people care to report ⁜ Re-applied some patches still not merged upstream, including the legal ⚖ one ⚙ It builds, what can go wrong⁉ ⁂ Changed Huey policy file. Huey users, please test [ 1 ] Bug #491853 - CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583 https://bugzilla.redhat.com/show_bug.cgi?id=491853 su -c 'yum update argyllcms' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-announce

Change Log

References

Update Instructions

Severity
Product : Fedora 9
Version : 1.0.3
Release : 4.fc9
URL : http://www.argyllcms.com/
Summary : ICC compatible color management system

Related News