Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2018-16435

Published: 3 September 2018

Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

Priority

Medium

CVSS 3 base score: 5.5

Status

Package Release Status
chromium-browser
Launchpad, Ubuntu, Debian
bionic
Released (69.0.3497.81-0ubuntu0.18.04.1)
cosmic
Released (69.0.3497.81-0ubuntu1)
disco
Released (69.0.3497.81-0ubuntu1)
precise Does not exist

trusty Does not exist
(trusty was ignored [no longer updated])
upstream
Released (69.0.3497.81-1)
xenial
Released (69.0.3497.81-0ubuntu0.16.04.1)
lcms
Launchpad, Ubuntu, Debian
bionic Does not exist

cosmic Does not exist

disco Does not exist

precise
Released (1.19.dfsg-1ubuntu3.1)
trusty Does not exist
(trusty was needs-triage)
upstream Needs triage

xenial Does not exist

Patches:
upstream: https://github.com/mm2/Little-CMS/commit/768f70ca405cd3159d990e962d54456773bb8cf8

lcms2
Launchpad, Ubuntu, Debian
bionic
Released (2.9-1ubuntu0.1)
cosmic
Released (2.9-3)
disco
Released (2.9-3)
precise
Released (2.2+git20110628-2ubuntu3.3)
trusty
Released (2.5-0ubuntu4.2)
upstream Needs triage

xenial
Released (2.6-3ubuntu2.1)
Patches:

upstream: https://github.com/mm2/Little-CMS/commit/768f70ca405cd3159d990e962d54456773bb8cf8
oxide-qt
Launchpad, Ubuntu, Debian
bionic Does not exist

cosmic Does not exist

disco Does not exist

precise Does not exist

trusty Does not exist
(trusty was ignored [Ubuntu touch end-of-life])
upstream Needs triage

xenial Ignored
(Ubuntu touch end-of-life)