Oval Definition:oval:com.redhat.rhsa:def:20090339
Revision Date:2009-03-19Version:644
Title:RHSA-2009:0339: lcms security update (Moderate)
Description:Little Color Management System (LittleCMS, or simply "lcms") is a small-footprint, speed-optimized open source color management engine.

  • Multiple integer overflow flaws which could lead to heap-based buffer overflows, as well as multiple insufficient input validation flaws, were found in LittleCMS. An attacker could use these flaws to create a specially-crafted image file which could cause an application using LittleCMS to crash, or, possibly, execute arbitrary code when opened by a victim. (CVE-2009-0723, CVE-2009-0733)

  • A memory leak flaw was found in LittleCMS. An application using LittleCMS could use excessive amount of memory, and possibly crash after using all available memory, if used to open specially-crafted images. (CVE-2009-0581)

    Red Hat would like to thank Chris Evans from the Google Security Team for reporting these issues.

    All users of LittleCMS should install these updated packages, which upgrade LittleCMS to version 1.18. All running applications using the lcms library must be restarted for the update to take effect.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2009-0581
    CVE-2009-0723
    CVE-2009-0733
    RHSA-2009:0339
    RHSA-2009:0339-01
    RHSA-2009:0339-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND
  • lcms is earlier than 0:1.18-0.1.beta1.el5_3.2
  • AND lcms is signed with Red Hat redhatrelease2 key
  • lcms-devel is earlier than 0:1.18-0.1.beta1.el5_3.2
  • AND lcms-devel is signed with Red Hat redhatrelease2 key
  • python-lcms is earlier than 0:1.18-0.1.beta1.el5_3.2
  • AND python-lcms is signed with Red Hat redhatrelease2 key
  • BACK