USN-3770-2: Little CMS vulnerabilities
20 September 2018
Several security issues were fixed in Little CMS.
Releases
Packages
Details
USN-3770-1 fixed a vulnerability in Little CMS. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Pedro Ribeiro discoreved that Little CMS incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2013-4276)
Ibrahim El-Sayed discovered that Little CMS incorrectly handled certain files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2016-10165)
Quang Nguyen discovered that Little CMS incorrectly handled certain files.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2018-16435)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.04
-
liblcms2-utils
-
2.2+git20110628-2ubuntu3.3
-
liblcms-utils
-
1.19.dfsg-1ubuntu3.1
-
liblcms2-2
-
2.2+git20110628-2ubuntu3.3
-
liblcms1
-
1.19.dfsg-1ubuntu3.1
After a standard system update you need to restart applications using Little
CMS to make all the necessary changes.
References
Related notices
- USN-3770-1: lcms2, liblcms2-utils, liblcms2-dev, liblcms2-2