REDHAT-BUG-992975: Buffer Overflow
Three (two in ColorSpace conversion calculator, one in TIFF compare utility) stack-based buffer overflow flaws were found in the way icctrans / tiffdiff tools of LittleCMS, the color management system, used to process certain ICC color profile / TIFF image format files. Remote attacker could provide a specially-crafted ICC color profile / TIFF image format files that, when opened in color space conversion calculator (icctrans) or TIFF compare utility (tiffdiff) of LittleCMS would lead to that utility crash.
References: [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=718682 [2] http://www.openwall.com/lists/oss-security/2013/08/05/2
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-992975?
The severity of REDHAT-BUG-992975 is considered high due to the presence of stack-based buffer overflow vulnerabilities.
How do I fix REDHAT-BUG-992975?
To fix REDHAT-BUG-992975, update to the latest version of the LittleCMS software where the vulnerabilities are patched.
What tools are affected by REDHAT-BUG-992975?
The tools affected by REDHAT-BUG-992975 are icctrans and tiffdiff from the LittleCMS color management system.
What types of vulnerabilities are described in REDHAT-BUG-992975?
REDHAT-BUG-992975 describes stack-based buffer overflow vulnerabilities in the processing of certain ICC color profile and TIFF image files.
Can a remote attacker exploit REDHAT-BUG-992975?
Yes, a remote attacker could exploit REDHAT-BUG-992975 by providing specially crafted ICC color profile or TIFF files.