Debian Security Advisory
DSA-3774-1 lcms2 -- security update
- Date Reported:
- 29 Jan 2017
- Affected Packages:
- lcms2
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 852627.
In Mitre's CVE dictionary: CVE-2016-10165. - More information:
-
Ibrahim M. El-Sayed discovered an out-of-bounds heap read vulnerability in the function Type_MLU_Read in lcms2, the Little CMS 2 color management library, which can be triggered by an image with a specially crafted ICC profile and leading to a heap memory leak or denial-of-service for applications using the lcms2 library.
For the stable distribution (jessie), this problem has been fixed in version 2.6-3+deb8u1.
For the testing distribution (stretch) and the unstable distribution (sid), this problem has been fixed in version 2.8-4.
We recommend that you upgrade your lcms2 packages.