Updated lcms2 packages fix security vulnerability
Publication date: 21 Sep 2018Modification date: 21 Sep 2018
Type: security
Affected Mageia releases : 6
CVE: CVE-2018-16435
Description
Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile. (CVE-2018-16435)
References
SRPMS
6/core
- lcms2-2.8-2.1.mga6