Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1628969 - (CVE-2018-16435) CVE-2018-16435 lcms2: Integer overflow in AllocateDataSet() in cmscgats.c leading to heap-based buffer overflow
CVE-2018-16435 lcms2: Integer overflow in AllocateDataSet() in cmscgats.c lea...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180813,repor...
: Security
: 1640118 (view as bug list)
Depends On: 1628971 1628973 1640121 1640122 1628970 1628972 1640120
Blocks: 1628975
  Show dependency treegraph
 
Reported: 2018-09-14 10:32 EDT by Laura Pardo
Modified: 2018-10-28 23:50 EDT (History)
19 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:3004 None None None 2018-10-24 18:08 EDT

  None (edit)
Description Laura Pardo 2018-09-14 10:32:11 EDT
A flaw was found in Little CMS (aka Little Color Management System) 2.9. An integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.


References:
https://github.com/mm2/Little-CMS/issues/171

Upstream Fix:
https://github.com/mm2/Little-CMS/commit/768f70ca405cd3159d990e962d54456773bb8cf8
Comment 1 Laura Pardo 2018-09-14 10:33:17 EDT
Created lcms2 tracking bugs for this issue:

Affects: epel-6 [bug 1628972]
Affects: fedora-all [bug 1628970]


Created mingw-lcms2 tracking bugs for this issue:

Affects: fedora-all [bug 1628971]
Comment 7 Tomas Hoger 2018-10-24 09:13:54 EDT
*** Bug 1640118 has been marked as a duplicate of this bug. ***
Comment 8 errata-xmlrpc 2018-10-24 18:08:06 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6 Supplementary

Via RHSA-2018:3004 https://access.redhat.com/errata/RHSA-2018:3004

Note You need to log in before you can comment on or make changes to this bug.