GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Thu May 27, 2021 12:26 am Post subject: [ GLSA 202105-18 ] LittleCMS |
|
|
Gentoo Linux Security Advisory
Title: LittleCMS: User-assisted execution of arbitrary code (GLSA 202105-18)
Severity: normal
Exploitable: local, remote
Date: 2021-05-26
Bug(s): #761418
ID: 202105-18
Synopsis
A heap-based buffer overflow in LittleCMS might allow remote
attackers to execute arbitrary code.
Background
LittleCMS, or short lcms, is a color management system for working with
ICC profiles. It is used by many applications including GIMP, Firefox and
Chromium.
Affected Packages
Package: media-libs/lcms
Vulnerable: < 2.10
Unaffected: >= 2.10
Architectures: All supported architectures
Description
It was discovered that LittleCMS (aka Little Color Management System)
had an integer overflow in the AllocateDataSet function in cmscgats.c.
Impact
A remote attacker could entice a user or automated system to open a
specially crafted file containing malicious color data, possibly
resulting in execution of arbitrary code with the privileges of the
process or a Denial of Service condition.
Workaround
There is no known workaround at this time.
Resolution
All LittleCMS users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/lcms-2.10"
|
References
CVE-2018-16435 |
|