Bug 992975 (CVE-2013-4276)
| Summary: | CVE-2013-4276 lcms: Stack-based buffer overflows in ColorSpace conversion calculator and TIFF compare utility | ||||||
|---|---|---|---|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Jan Lieskovsky <jlieskov> | ||||
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> | ||||
| Status: | CLOSED ERRATA | QA Contact: | |||||
| Severity: | medium | Docs Contact: | |||||
| Priority: | medium | ||||||
| Version: | unspecified | CC: | andreas.bierfert, dbhole, pedrib, rhughes | ||||
| Target Milestone: | --- | Keywords: | Security | ||||
| Target Release: | --- | ||||||
| Hardware: | All | ||||||
| OS: | Linux | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2021-10-20 10:40:11 UTC | Type: | --- | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Bug Depends On: | 992978, 992979 | ||||||
| Bug Blocks: | 992984, 1000074 | ||||||
| Attachments: |
|
||||||
|
Description
Jan Lieskovsky
2013-08-05 10:41:50 UTC
This issue affects the (latest) versions of the lcms package, as shipped with Red Hat Enterprise Linux 5 and 6. -- This issue affects the (latest) versions of the lcms package, as shipped with Fedora release of 18 and 19. Please schedule an update (once there's final patch version agreement available). Created attachment 782749 [details] Proposed patch from Debian bug #718682 which is reported to having issues: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=718682#10 Created lcms tracking bugs for this issue: Affects: fedora-all [bug 992979] *** Bug 991757 has been marked as a duplicate of this bug. *** This was assigned CVE-2013-4276: http://www.openwall.com/lists/oss-security/2013/08/22/3 lcms-1.19-13.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report. |