CVE-2012-1616
Publication date 21 June 2012
Last updated 24 July 2024
Ubuntu priority
Description
Use-after-free vulnerability in icclib before 2.13, as used by Argyll CMS before 1.4 and possibly other programs, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted ICC profile file.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| argyll | ||
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |
| libicc | ||
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
References
Other references
- https://bugzilla.redhat.com/show_bug.cgi?id=809697
- http://xforce.iss.net/xforce/xfdb/75162
- http://www.argyllcms.com/icc_readme.html
- http://security.gentoo.org/glsa/glsa-201206-04.xml
- http://secunia.com/advisories/49602
- http://secunia.com/advisories/48921
- https://www.cve.org/CVERecord?id=CVE-2012-1616