First published: Thu Mar 19 2009(Updated: )
Little Color Management System (LittleCMS, or simply "lcms") is a<br>small-footprint, speed-optimized open source color management engine.<br>Multiple integer overflow flaws which could lead to heap-based buffer<br>overflows, as well as multiple insufficient input validation flaws, were<br>found in LittleCMS. An attacker could use these flaws to create a<br>specially-crafted image file which could cause an application using<br>LittleCMS to crash, or, possibly, execute arbitrary code when opened by a<br>victim. (CVE-2009-0723, CVE-2009-0733)<br>A memory leak flaw was found in LittleCMS. An application using LittleCMS<br>could use excessive amount of memory, and possibly crash after using all<br>available memory, if used to open specially-crafted images. (CVE-2009-0581)<br>Red Hat would like to thank Chris Evans from the Google Security Team for<br>reporting these issues.<br>All users of LittleCMS should install these updated packages, which upgrade<br>LittleCMS to version 1.18. All running applications using the lcms library<br>must be restarted for the update to take effect.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/lcms | <1.18-0.1.beta1.el5_3.2 | 1.18-0.1.beta1.el5_3.2 |
redhat/lcms | <1.18-0.1.beta1.el5_3.2 | 1.18-0.1.beta1.el5_3.2 |
redhat/lcms-devel | <1.18-0.1.beta1.el5_3.2 | 1.18-0.1.beta1.el5_3.2 |
redhat/lcms-devel | <1.18-0.1.beta1.el5_3.2 | 1.18-0.1.beta1.el5_3.2 |
redhat/python-lcms | <1.18-0.1.beta1.el5_3.2 | 1.18-0.1.beta1.el5_3.2 |
redhat/python-lcms | <1.18-0.1.beta1.el5_3.2 | 1.18-0.1.beta1.el5_3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2009:0339 is considered important due to potential exploitation leading to security vulnerabilities.
To fix RHSA-2009:0339, you should upgrade to the specified version 1.18-0.1.beta1.el5_3.2 of the affected packages.
RHSA-2009:0339 affects packages including lcms, lcms-devel, and python-lcms on applicable Red Hat systems.
RHSA-2009:0339 addresses multiple integer overflow flaws and insufficient input validation issues in LittleCMS.
Yes, there is a risk of remote code execution and denial of service if the vulnerabilities in RHSA-2009:0339 are exploited.