A heap buffer overflow flaw was found in the Little CMS in PDFium component of the Chromium browser. Upstream bug: https://crbug.com/872189 External References: https://chromereleases.googleblog.com/2018/10/stable-channel-update-for-desktop.html
Created chromium tracking bugs for this issue: Affects: epel-7 [bug 1640122] Affects: fedora-all [bug 1640121]
(In reply to Andrej Nemec from comment #0) > https://crbug.com/872189 The upstream chromium bug is still not public, but using the bug id, the following commit in the chromium repo: https://chromium.googlesource.com/chromium/src/+/6486b858d8c49db25df193a817b808d4dcea1f75%5E%21/#F0 points us to the pdfium repo, which contains the following commit: https://pdfium.googlesource.com/pdfium.git/+/81a3c2408a1fb3e3cc4b06d659cce19157ee0a91%5E%21/#F1 which corresponds to the following LittleCMS / lcms upstream commit: https://github.com/mm2/Little-CMS/commit/768f70ca making this a duplicate of bug 1628969 / CVE-2018-16435. *** This bug has been marked as a duplicate of bug 1628969 ***