REDHAT-BUG-1628969: Buffer Overflow
A flaw was found in Little CMS (aka Little Color Management System) 2.9. An integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.
References: https://github.com/mm2/Little-CMS/issues/171
Upstream Fix: https://github.com/mm2/Little-CMS/commit/768f70ca405cd3159d990e962d54456773bb8cf8
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1628969?
REDHAT-BUG-1628969 is classified as a high severity vulnerability due to the potential for remote code execution via heap-based buffer overflow.
How do I fix REDHAT-BUG-1628969?
To fix REDHAT-BUG-1628969, you should update to the latest version of Little CMS that addresses this integer overflow vulnerability.
What does REDHAT-BUG-1628969 affect?
REDHAT-BUG-1628969 affects versions of the Little Color Management System, specifically version 2.9.
What is the impact of exploiting REDHAT-BUG-1628969?
Exploiting REDHAT-BUG-1628969 could allow an attacker to execute arbitrary code on the affected system.
How was REDHAT-BUG-1628969 discovered?
REDHAT-BUG-1628969 was discovered through static code analysis which identified an integer overflow leading to a buffer overflow.