Mageia 2018-0387: lcms2 security update
Summary
Little CMS (aka Little Color Management System) 2.9 has an integer overflow
in the AllocateDataSet function in cmscgats.c, leading to a heap-based
buffer overflow in the SetData function via a crafted file in the second
argument to cmsIT8LoadFromFile. (CVE-2018-16435)
References
- https://bugs.mageia.org/show_bug.cgi?id=23533
- https://www.debian.org/security/2018/dsa-4284
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16435
Resolution
MGASA-2018-0387 - Updated lcms2 packages fix security vulnerability
SRPMS
- 6/core/lcms2-2.8-2.1.mga6