REDHAT-BUG-487508: Integer Overflow
Chris Evans discovered an integer overflow flaw in LittleCms. This flaw could potentially lead to arbitrary code execution in applications that use the system LittleCms library, or embed the source into their application.
Acknowledgements:
Red Hat would like to thank Chris Evans from the Google Security Team for reporting these issues.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-487508?
The severity of REDHAT-BUG-487508 is considered high due to the potential for arbitrary code execution.
How do I fix REDHAT-BUG-487508?
To fix REDHAT-BUG-487508, update to the latest version of LittleCms that addresses this integer overflow flaw.
What causes the vulnerability in REDHAT-BUG-487508?
The vulnerability in REDHAT-BUG-487508 is caused by an integer overflow flaw in the LittleCms library.
Who discovered the vulnerability in REDHAT-BUG-487508?
The vulnerability in REDHAT-BUG-487508 was discovered by Chris Evans.
What types of applications are affected by REDHAT-BUG-487508?
Applications that use the system LittleCms library or embed it are affected by REDHAT-BUG-487508.