Several security issues were fixed in Little CMS.. =========================================================================Ubuntu Security Notice USN-3770-2 September 20, 2018 lcms, lcms2 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: Several security issues were fixed in Little CMS. Software Description: - lcms: Little CMS color management library utilities - lcms2: Little CMS color management library Details: USN-3770-1 fixed a vulnerability in Little CMS. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: Pedro Ribeiro discoreved that Little CMS incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. (CVE-2013-4276) Ibrahim El-Sayed discovered that Little CMS incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. (CVE-2016-10165) Quang Nguyen discovered that Little CMS incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2018-16435) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: liblcms-utils 1.19.dfsg-1ubuntu3.1 liblcms1 1.19.dfsg-1ubuntu3.1 liblcms2-2 2.2+git20110628-2ubuntu3.3 liblcms2-utils 2.2+git20110628-2ubuntu3.3 After a standard system update you need to restart applications using Little CMS to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3770-2 https://ubuntu.com/security/notices/USN-3770-1 CVE-2013-4276, CVE-2016-10165, CVE-2018-16435 . Several vulnerabilities detected inLittle CMS on Ubuntu 12.04 ESM necessitate immediate patches to ensure security against potential exploits.. Little CMS, Ubuntu Updates, Denial of Service Risks, Security Patch. . Severity: Critical. LinuxSecurity.com Team
* apply patch for CVE-2013-4276 * apply patch for "Use of uninitialized values on 64 bit machines.". -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-1648 2015-02-04 04:31:04 -------------------------------------------------------------------------------- Name : lcms Product : Fedora 20 Version : 1.19 Release : 13.fc20 URL : https://www.littlecms.com/ Summary : Color Management System Description : LittleCMS intends to be a small-footprint, speed optimized color management engine in open source form. -------------------------------------------------------------------------------- Update Information: * apply patch for CVE-2013-4276 * apply patch for "Use of uninitialized values on 64 bit machines." -------------------------------------------------------------------------------- ChangeLog: * Sun Aug 17 2014 Fedora Release Engineering - 1.19-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild * Sat Jun 7 2014 Fedora Release Engineering - 1.19-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Mon Dec 9 2013 Michael Schwendt - 1.19-11 - apply patch for CVE-2013-4276 (#991757, #992979) - apply patch for "Use of uninitialized values on 64 bit machines." (#1003950) - add %_isa in -libs base package deps - drop %defattr usage * Wed Sep 4 2013 Nils Philippsen - fix bogus dates in changelog -------------------------------------------------------------------------------- References: [ 1 ] Bug #992975 - CVE-2013-4276 lcms: Stack-based buffer overflows in ColorSpace conversion calculator and TIFF compare utility https://bugzilla.redhat.com/show_bug.cgi?id=992975 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update lcms' at the command line. For more information, refer to "Managing Software with yum", available at . All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
It was discovered that a NULL pointer dereference in the code forhandling transformations of monochrome profiles could allow an attackerto cause a denial of service through a specially crafted image.(CVE-2009-0793) [More...]. ==========================================================Ubuntu Security Notice USN-1043-1 January 12, 2011 lcms vulnerability CVE-2009-0793 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 9.10 Ubuntu 10.04 LTS Ubuntu 10.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: liblcms1 1.16-7ubuntu1.3 Ubuntu 9.10: liblcms1 1.18.dfsg-1ubuntu1.1 Ubuntu 10.04 LTS: liblcms1 1.18.dfsg-1ubuntu2.10.04.1 Ubuntu 10.10: liblcms1 1.18.dfsg-1ubuntu2.10.10.1 In general, a standard system update will make all the necessary changes. Details follow: It was discovered that a NULL pointer dereference in the code for handling transformations of monochrome profiles could allow an attacker to cause a denial of service through a specially crafted image. (CVE-2009-0793) Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 26887 e6f7f18b9c8c161cb28b1050ae37a7dc Size/MD5: 1651 061a51a9590122c929a55f97c9af18fe Size/MD5: 911546 b07b623f3e712373ff713fb32cf23651 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 670522 387faeb68c6f2905f4d4dc2e92281394 Size/MD5: 102812 6c0de134fe6e13d9084017c8a848948a Size/MD5: 58336 faea24641f0e5dc794162a38b8094fbf Size/MD5: 160930 658fad1a8975dfa01c7c339f57dedff2 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 623192 b25d76f8313405e1769b4d90fbedb59c Size/MD5: 96346573a2703a7a72dce8eac9814eefd972e Size/MD5: 55076 889cd8eea3a342112ebde9cb1f64ddaa Size/MD5: 151876 193ce09714ae6406c9cb3fc651f5db37 lpia architecture (Low Power Intel Architecture): Size/MD5: 629032 f61b32be0b27f2e22a8ba6900adcba69 Size/MD5: 95696 b09d6d68c67b6059af6c1f66cde7532d Size/MD5: 55482 e03b3e83151acf00e8424be1fa559c27 Size/MD5: 148576 eea063a2108327909f558a7557472655 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 756434 602ae82dcfe35b986dc0d6d7b91953b0 Size/MD5: 111268 ef7755b8247f285f679e19e317107992 Size/MD5: 72292 4cfe0928f7f1e79300384fea59b547bc Size/MD5: 169436 4f66b2ebaace414adb1b92c9b30c1130 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 655626 d02eadf3af5519883a25e056fdaafce1 Size/MD5: 98876 f9edda48f4d3051452fb694f2f05c1df Size/MD5: 57910 b32b9a857d42b1b0578d749d166b878e Size/MD5: 159914 d77eeb49466255f257aa1e11cc696a5f Updated packages for Ubuntu 9.10: Source archives: Size/MD5: 9795 2a5bc68b26b8727643fbb5ea97a74b3b Size/MD5: 2024 cf857a038ae254d4b107c5d81d6cf64b Size/MD5: 894456 2d4078499413febf56db0bcc1d8d4eb9 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 202526 6348d916764c5cb8f6382079843f324a Size/MD5: 110408 f9c75298dba3171ba1109b1120ad0831 Size/MD5: 62414 8d3b0a4822016b31a2bb1214a183a75a Size/MD5: 157812 ab4a2662a35f8909c2c0dfbf35122963 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 195170 5256a4ac32e45fb6e08331b736e25aad Size/MD5: 103200 583eba21821f02dd1c65a6df84f970c8 Size/MD5: 56996 aaf30568cb8da7faf3a07650445874c7 Size/MD5: 151354 13d4ece3945be36a6f440f50195c827b armel architecture (ARM Architecture): Size/MD5: 190306 8d22c071ec2838bb21302efdcbeb626d Size/MD5: 1023322c29a8beaece5d77c988725e7c6b25ee Size/MD5: 57332 f4d5286b2a3bc760af9cd5c405dc2d93 Size/MD5: 134906 41d7f494e2ace18cbbf4c3b86fda3359 lpia architecture (Low Power Intel Architecture): Size/MD5: 190880 361076583a35d44798ce89d5638adf91 Size/MD5: 101256 bfcb8f35dcefa052b08bbd5e5728ccae Size/MD5: 57728 c4f8b20d28d231af6c16e226c403ffe5 Size/MD5: 147322 f80f89bd1b6babf76e71f90b86d40e42 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 203148 d8506d1f197640d414916324fa4267d5 Size/MD5: 114880 2ed6d9e05b95392506086045306fd3cb Size/MD5: 59120 b2e59befb313a9aa02a524153529d79a Size/MD5: 165064 0a390a3e26bbbac204169e9a33a8b70f sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 201662 210aec30d1353f9a3f2d6fb3f1984236 Size/MD5: 106348 8621813760664bb1be69ccc10dc193c4 Size/MD5: 62910 84de59111b2ffc6af10604c8dbf2f918 Size/MD5: 157730 2e8617fa92b8fe5a1b3408606e0aedc4 Updated packages for Ubuntu 10.04 LTS: Source archives: Size/MD5: 9897 50c87fff6501f9194d8417254fbeaa00 Size/MD5: 2048 6316f6fdaca98550248d454f218c8aa8 Size/MD5: 894456 2d4078499413febf56db0bcc1d8d4eb9 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 202574 4e5ca751960544d924b6121281992160 Size/MD5: 110512 5206b4b12680e17805854d22ceda3937 Size/MD5: 62666 49174698da1bfbe2d92f81a5ec14d343 Size/MD5: 160052 9656fec5eb5151ec51aa5d3db5ec99c2 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 195106 cd26a05adb7ccae9d3d63200d743f788 Size/MD5: 103198 5c206024aa735e47cc50fd87d475e2e2 Size/MD5: 57140 4599e95ee9101596195863e723e5093a Size/MD5: 153566 a11f5a31a4246f0a385e6c9d9ea7ab83 armel architecture (ARM Architecture): Size/MD5: 181894 0c3fe9347b13d10251b14c3d22037275 Size/MD5: 97396a7275c6d01601e9ba3a36c0f46e38dee Size/MD5: 56768 59f92a7982c01a2340547d093930373b Size/MD5: 137474 7af33a654f466ffe55554f05b3652bf6 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 203320 1d35c8ed6530d60354667944d75ce757 Size/MD5: 115178 4f7d8c233e5f27e0794fd2a1f753fb7d Size/MD5: 59198 5354d3f927fb0957a7280ad20522cd5f Size/MD5: 167004 4181e185eb4290f4a506cc6a5ef23332 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 206764 60b6b0499d3d70b45b0c12e160ccfaea Size/MD5: 110080 ee7259f8b863616c4fc1d5a85695b5ea Size/MD5: 64514 7d23af820f62f7efdcadcb8e08d3675d Size/MD5: 159334 974383cd3fd688a1003ec99b3a9113b6 Updated packages for Ubuntu 10.10: Source archives: Size/MD5: 10114 20e7514ba0acbe330b94a4cbce98c605 Size/MD5: 2051 fafeffac18c542d6de316209251f73ad Size/MD5: 894456 2d4078499413febf56db0bcc1d8d4eb9 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 202754 cfdbfd84af2006dc76a1372cd15f6190 Size/MD5: 109764 abd8626f2895847dcfa2ab2ab6159797 Size/MD5: 60076 f1a2fa552f9e06608800457d84fcba5c Size/MD5: 159182 8bd5175d44cc41372d483d3c6f5826f4 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 194744 f32a720f427204fed94e710d68af64fa Size/MD5: 101774 18c07cb47c8aa5d98eea25a88addb09e Size/MD5: 55894 6eb6f435d3fb932825a889cb907a61eb Size/MD5: 150354 5bd5c8298068a83dc7d4340899d3cdbf armel architecture (ARM Architecture): Size/MD5: 193432 2385281b25960d18f6c11fed43bd5db3 Size/MD5: 107328 48594ec3346b71b7f8d57654f011dc88 Size/MD5: 57502 167efcb36ab71e3d7ffb5d02ccd6d2b3 Size/MD5: 139296 cf71751aeb49497b7c277faa31f02d81 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 203088 05a41447398de2349516957ec6bfcd9c Size/MD5: 114178c62a0f29535d5422ede2b40daeb75ca2 Size/MD5: 57940 53f47bd1f12f0f15faf1e04cd4827dc9 Size/MD5: 166136 d069de5b989d6d11fff002a0f823e0f3 . Ubuntu Security Bulletin USN-1043-1: Mitigating the lcms vulnerability within Ubuntu to avoid potential service interruptions caused by manipulated image files.. Ubuntu, lcms, denial of service. . Severity: Important. LinuxSecurity.com Team
CVE-2009-0793 The patch was given by lcms upstream on the lcms announce mailing list. % 40littlecms.com. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-3967 2009-04-27 20:37:49 -------------------------------------------------------------------------------- Name : lcms Product : Fedora 10 Version : 1.18 Release : 2.fc10 URL : https://www.littlecms.com/ Summary : Color Management System Description : LittleCMS intends to be a small-footprint, speed optimized color management engine in open source form. -------------------------------------------------------------------------------- Update Information: CVE-2009-0793 The patch was given by lcms upstream on the lcms announce mailing list. % 40littlecms.com -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 22 2009 kwizart < kwizart at gmail.com > - 1.18-2 - Add lcms-CVE-2009-0793.patch from 1.18a * Mon Mar 23 2009 kwizart < kwizart at gmail.com > - 1.18-1 - Update to 1.18 (final) - Remove upstreamed patches - Disable autoreconf - patch libtool to prevent rpath issue * Fri Mar 20 2009 kwizart < kwizart at gmail.com > - 1.18-0.1.beta2 - Update to 1.18beta2 fix bug #487508: CVE-2009-0723 LittleCms integer overflow fix bug #487512: CVE-2009-0733 LittleCms lack of upper-bounds check on sizes fix bug #487509: CVE-2009-0581 LittleCms memory leak * Mon Mar 2 2009 kwizart < kwizart at gmail.com > - 1.17-10 - Fix circle dependency #452352 * Wed Feb 25 2009 Fedora Release Engineering - 1.17-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Thu Dec 4 2008 kwizart < kwizart at gmail.com > - 1.17-8 - Fix autoreconf and missing auxiliary files. * Sat Nov 29 2008 Ignacio Vazquez-Abrams - 1.17-7 - Rebuild for Python 2.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #492353 - CVE-2009-0793 lcms: Null pointer dereference (DoS)by handling transformations of monochrome profiles https://bugzilla.redhat.com/show_bug.cgi?id=492353 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update lcms' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
CVE-2009-0793 The patch was given by lcms upstream on the lcms announce mailing list. % 40littlecms.com. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-3914 2009-04-27 20:37:14 -------------------------------------------------------------------------------- Name : lcms Product : Fedora 9 Version : 1.18 Release : 2.fc9 URL : https://www.littlecms.com/ Summary : Color Management System Description : LittleCMS intends to be a small-footprint, speed optimized color management engine in open source form. -------------------------------------------------------------------------------- Update Information: CVE-2009-0793 The patch was given by lcms upstream on the lcms announce mailing list. % 40littlecms.com -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 22 2009 kwizart < kwizart at gmail.com > - 1.18-2 - Add lcms-CVE-2009-0793.patch from 1.18a * Mon Mar 23 2009 kwizart < kwizart at gmail.com > - 1.18-1 - Update to 1.18 (final) - Remove upstreamed patches - Disable autoreconf - patch libtool to prevent rpath issue * Fri Mar 20 2009 kwizart < kwizart at gmail.com > - 1.18-0.1.beta2 - Update to 1.18beta2 fix bug #487508: CVE-2009-0723 LittleCms integer overflow fix bug #487512: CVE-2009-0733 LittleCms lack of upper-bounds check on sizes fix bug #487509: CVE-2009-0581 LittleCms memory leak * Mon Mar 2 2009 kwizart < kwizart at gmail.com > - 1.17-10 - Fix circle dependency #452352 * Wed Feb 25 2009 Fedora Release Engineering - 1.17-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Thu Dec 4 2008 kwizart < kwizart at gmail.com > - 1.17-8 - Fix autoreconf and missing auxiliary files. * Sat Nov 29 2008 Ignacio Vazquez-Abrams - 1.17-7 - Rebuild for Python 2.6 * Tue Oct 28 2008 kwizart < kwizart at gmail.com > - 1.17-6 - Add lcms-fix_s390_lcms_h.patch - Fix #468245 * Tue Jun 3 2008 kwizart < kwizart at gmail.com > -1.17-5 - Fix Array indexing error in ReadCurve - #448066 -------------------------------------------------------------------------------- References: [ 1 ] Bug #492353 - CVE-2009-0793 lcms: Null pointer dereference (DoS) by handling transformations of monochrome profiles https://bugzilla.redhat.com/show_bug.cgi?id=492353 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update lcms' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
This update fixes a possible regression introduced in DSA-1745-1 and also enhances the security patch. For reference the original advisory text is below. . - ------------------------------------------------------------------------ Debian Security Advisory DSA-1745-2
lcms in OpenJDK upgraded to 1.18 fixing many related security issues.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-3034 2009-03-25 15:23:33 --------------------------------------------------------------------------------Name : java-1.6.0-openjdk Product : Fedora 9 Version : 1.6.0.0 Release : 0.23.b09.fc9 URL : https://icedtea.classpath.org/ Summary : OpenJDK Runtime Environment Description : The OpenJDK runtime environment. --------------------------------------------------------------------------------Update Information: lcms in OpenJDK upgraded to 1.18 fixing many related security issues. --------------------------------------------------------------------------------ChangeLog: * Tue Mar 24 2009 Lillian Angel - 1:1.6.0-0.23.b09 - Updated java-1.6.0-openjdk-lcms.patch. * Tue Mar 24 2009 Lillian Angel - 1:1.6.0-0.22.b09 - Updated release. - Added java-1.6.0-openjdk-securitypatches.patch. * Fri Mar 20 2009 Lillian Angel - 1:1.6.0-0.21.b09 - Added new lcms security patch. * Tue Dec 2 2008 Lillian Angel - 1:1.6.0-0.20.b09 - Set runtests to 0. * Tue Dec 2 2008 Lillian Angel - 1:1.6.0-0.20.b09 - Added new security patch. - Resolves: rhbz#472234 - Resolves: rhbz#472233 - Resolves: rhbz#472231 - Resolves: rhbz#472228 - Resolves: rhbz#472224 - Resolves: rhbz#472218 - Resolves: rhbz#472213 - Resolves: rhbz#472212 - Resolves: rhbz#472211 - Resolves: rhbz#472209 - Resolves: rhbz#472208 - Resolves: rhbz#472206 - Resolves: rhbz#472201 * Mon Sep 22 2008 Lillian Angel - 1:1.6.0-0.19.b09 - Removed update-desktop-database dependency. - Resolves: rhbz#463046 * Mon Sep 8 2008 Lillian Angel - 1:1.6.0-0.18.b09 - Moved hotspot patch to only be applied to jit_arches. * Mon Sep 8 2008 Lillian Angel - 1:1.6.0-0.18.b09 - Added hotspot patch (Patch11) to fix eclipse crashing bug. - Resolves: rhbz#460205 * Mon Sep 8 2008 Lillian Angel -1:1.6.0-0.18.b09 - Added rhino requirement. - Resolves: rhbz#461336 * Wed Jul 16 2008 Dennis Gilmore - 1:1.6.0-0.17.b09 - bump the release to sync all arches * Wed Jul 9 2008 Lillian Angel - 1:1.6.0-0.16.b09 - Add runtests define. - Run test suites on JIT architectures only. * Tue Jul 8 2008 Lillian Angel - 1:1.6.0-0.16.b09 - Only apply hotspot security patch of jitarches. * Wed Jul 2 2008 Lillian Angel - 1:1.6.0-0.16.b09 - Added OpenJDK security patches. * Sat Jun 7 2008 Tom "spot" Callaway - 1:1.6.0-0.16.b09 - enable sparc/sparc64 builds * Sat May 31 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Fix keytool location passed to generate-cacerts.pl. * Fri May 30 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Generate cacerts file. * Fri May 30 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Remove jhat patch. * Fri May 30 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Remove makefile patch. - Update generate-fedora-zip.sh. * Fri May 30 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Formatting cleanups. * Fri May 30 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Group all Mauve commands. * Fri May 30 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Formatting cleanups. - Add jtreg_output to src subpackage. * Wed May 28 2008 Lillian Angel - 1:1.6.0.0-0.15.b09 - Updated icedteasnapshot for new release. * Tue May 27 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Require ca-certificates. - Symlink to ca-certificates cacerts. - Remove cacerts from files list. - Resolves: rhbz#444260 * Mon May 26 2008 Lillian Angel - 1:1.6.0.0-0.14.b09 - Added eclipse-ecj build requirement for mauve. - Updated icedteasnapshot. * Fri May 23 2008 Lillian Angel - 1:1.6.0.0-0.14.b09 - Fixed jtreg testing. * Fri May 23 2008 Lillian Angel - 1:1.6.0.0-0.14.b09 - Updated icedteasnapshot. - Updated release. - Added jtreg testing. * Thu May 22 2008 Lillian Angel - 1:1.6.0.0-0.13.b09 - Added new patch java-1.6.0-openjdk-java-access-bridge-tck.patch. - Updatedrelease. * Mon May 5 2008 Lillian Angel - 1:1.6.0.0-0.12.b09 - Updated release. - Updated icedteasnapshot. - Resolves: rhbz#445182 - Resolves: rhbz#445183 * Tue Apr 29 2008 Lillian Angel - 1:1.6.0.0-0.11.b09 - Fixed javaws.desktop installation. * Tue Apr 29 2008 Lillian Angel - 1:1.6.0.0-0.11.b09 - Updated icedteasnapshot. - Removed java-1.6.0-openjdk-jconsole.desktop and java-1.6.0-openjdk-policytool.desktop files. * Tue Apr 29 2008 Lillian Angel - 1:1.6.0.0-0.11.b09 - Updated release. - Added archbuild and archinstall definitions for ia64. - Resolves: rhbz#433843 --------------------------------------------------------------------------------References: [ 1 ] Bug #487509 - CVE-2009-0581 LittleCms memory leak https://bugzilla.redhat.com/show_bug.cgi?id=487509 [ 2 ] Bug #487508 - CVE-2009-0723 LittleCms integer overflow https://bugzilla.redhat.com/show_bug.cgi?id=487508 [ 3 ] Bug #487512 - CVE-2009-0733 LittleCms lack of upper-bounds check on sizes https://bugzilla.redhat.com/show_bug.cgi?id=487512 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update java-1.6.0-openjdk' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
New lcms packages are available for Slackware 10.0, 10.1, 10.2, 11.0, 12.0, 12.1, 12.2, and -current to fix security issues. More details about the issues may be found in the Common Vulnerabilities and Exposures (CVE) database: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] lcms (SSA:2009-083-01) New lcms packages are available for Slackware 10.0, 10.1, 10.2, 11.0, 12.0, 12.1, 12.2, and -current to fix security issues. More details about the issues may be found in the Common Vulnerabilities and Exposures (CVE) database: https://www.cve.org/CVERecord?id=CVE-2009-0581 https://www.cve.org/CVERecord?id=CVE-2009-0723 https://www.cve.org/CVERecord?id=CVE-2009-0733 Here are the details from the Slackware 12.2 ChangeLog: +--------------------------+ patches/packages/lcms-1.18-i486-1_slack12.2.tgz: Upgraded to lcms-1.18. This update fixes security issues discovered in LittleCMS by Chris Evans. These flaws could cause program crashes (denial of service) or the execution of arbitrary code as the user of the lcms-linked program. For more information, see: https://www.cve.org/CVERecord?id=CVE-2009-0581 https://www.cve.org/CVERecord?id=CVE-2009-0723 https://www.cve.org/CVERecord?id=CVE-2009-0733 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com. Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 10.0: ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/lcms-1.18-i486-1_slack10.0.tgz Updated package for Slackware10.1: ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/lcms-1.18-i486-1_slack10.1.tgz Updated package for Slackware 10.2: ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/lcms-1.18-i486-1_slack10.2.tgz Updated package for Slackware 11.0: ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/lcms-1.18-i486-1_slack11.0.tgz Updated package for Slackware 12.0: ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/lcms-1.18-i486-1_slack12.0.tgz Updated package for Slackware 12.1: ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/lcms-1.18-i486-1_slack12.1.tgz Updated package for Slackware 12.2: ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/lcms-1.18-i486-1_slack12.2.tgz Updated package for Slackware -current: MD5 signatures: +-------------+ Slackware 10.0 package: 6a3369ac79791ca0999dbf57aed56207 lcms-1.18-i486-1_slack10.0.tgz Slackware 10.1 package: fbf182d254c740f688672713f64a17e5 lcms-1.18-i486-1_slack10.1.tgz Slackware 10.2 package: 2d96b95ba90abca6af5da84727078fc7 lcms-1.18-i486-1_slack10.2.tgz Slackware 11.0 package: 0814537987ca4994a4a331a3e47bcc98 lcms-1.18-i486-1_slack11.0.tgz Slackware 12.0 package: e6752bdf112b27d6c17758aaac7a02f6 lcms-1.18-i486-1_slack12.0.tgz Slackware 12.1 package: 9f8b2abb83ac254bb4c0fe85e519b02a lcms-1.18-i486-1_slack12.1.tgz Slackware 12.2 package: 70a303fa6a5aa390c09723153abf3589 lcms-1.18-i486-1_slack12.2.tgz Slackware -current package: 9b9ee19b1b2b1ada4ae15044d7218365 lcms-1.18-i486-1.tgz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg lcms-1.18-i486-1_slack12.2.tgz Then restart any daemons that are linked with lcms. +-----+ . Recent lcms updates for Slackware address critical vulnerabilities and improve overall system performance. Ensure you upgrade today!. Slackware Update,Lcms Packages,Service Issue,Security Fix. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.