REDHAT-BUG-487512: Medium severity LittleCms LittleCms vulnerability
Chris Evans discovered a flaw in how LittleCms checks certain upper-bounds sizes. This flaw could potentially lead to arbitrary code execution in applications that use the system LittleCms library, or embed the source into their application.
Acknowledgements:
Red Hat would like to thank Chris Evans from the Google Security Team for reporting these issues.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-487512?
REDHAT-BUG-487512 has a high severity level due to the potential for arbitrary code execution.
How do I fix REDHAT-BUG-487512?
You can fix REDHAT-BUG-487512 by updating to the patched version of the LittleCms library provided by Red Hat.
Which applications are affected by REDHAT-BUG-487512?
Applications that use the system LittleCms library or embed it in their code are affected by REDHAT-BUG-487512.
Who discovered the vulnerability REDHAT-BUG-487512?
The vulnerability REDHAT-BUG-487512 was discovered by Chris Evans.
What type of flaw is described in REDHAT-BUG-487512?
REDHAT-BUG-487512 describes a flaw in how LittleCms checks certain upper-bounds sizes.