Hide Forgot
A null pointer dereference flaw was found in LittleCMS by handling transformations of monochrome profiles. An attacker could use this flaw to create a specially-crafted image, which could cause an application using LittleCMS to crash, leading to a denial of service.
This issue has been addressed in the java-1.6.0-openjdk in following products: Red Hat Enterprise Linux 5 Via RHSA-2009:0377 https://rhn.redhat.com/errata/RHSA-2009-0377.html
java-1.6.0-openjdk-1.6.0.0-0.25.b09.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
java-1.6.0-openjdk-1.6.0.0-15.b14.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
lcms-1.18-2.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
lcms-1.18-2.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
Bug 542412 seems to suggest the lcms-1.18-3.fc12 patch is wrong.
Statement: (none)