MGASA-2018-0387 - Updated lcms2 packages fix security vulnerability

Publication date: 21 Sep 2018
URL: https://advisories.mageia.org/MGASA-2018-0387.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2018-16435

Little CMS (aka Little Color Management System) 2.9 has an integer overflow
in the AllocateDataSet function in cmscgats.c, leading to a heap-based
buffer overflow in the SetData function via a crafted file in the second
argument to cmsIT8LoadFromFile. (CVE-2018-16435)

References:
- https://bugs.mageia.org/show_bug.cgi?id=23533
- https://www.debian.org/security/2018/dsa-4284
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16435

SRPMS:
- 6/core/lcms2-2.8-2.1.mga6

Mageia 2018-0387: lcms2 security update

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData fu...

Summary

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile. (CVE-2018-16435)

References

- https://bugs.mageia.org/show_bug.cgi?id=23533

- https://www.debian.org/security/2018/dsa-4284

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16435

Resolution

MGASA-2018-0387 - Updated lcms2 packages fix security vulnerability

SRPMS

- 6/core/lcms2-2.8-2.1.mga6

Severity
Publication date: 21 Sep 2018
URL: https://advisories.mageia.org/MGASA-2018-0387.html
Type: security
CVE: CVE-2018-16435

Related News