REDHAT-BUG-1367357: Medium severity little cms vulnerability
An out-of-bounds read in cmstypes.c in TypeMLURead function was found, leading to heap memory leak triggered by crafted ICC profile.
Upstream patch:
https://github.com/mm2/Little-CMS/commit/5ca71a7bc18b6897ab21d815d15e218e204581e2
CVE request:
http://seclists.org/oss-sec/2016/q3/288
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1367357?
The severity of REDHAT-BUG-1367357 is high due to the potential for heap memory leaks from crafted ICC profiles.
How do I fix REDHAT-BUG-1367357?
To fix REDHAT-BUG-1367357, you should apply the upstream patch from the Little CMS GitHub repository.
What is the impact of REDHAT-BUG-1367357?
The impact of REDHAT-BUG-1367357 includes an out-of-bounds read that may lead to information disclosure via heap memory leaks.
Which versions of Little CMS are affected by REDHAT-BUG-1367357?
All versions of Little CMS prior to the application of the upstream patch are susceptible to REDHAT-BUG-1367357.
Is there a workaround for REDHAT-BUG-1367357?
No official workaround for REDHAT-BUG-1367357 has been released, so applying the patch is recommended.