Oval Definition:oval:org.mitre.oval:def:13131
Revision Date:2014-07-07Version:20
Title:USN-744-1 -- lcms vulnerabilities
Description:Chris Evans discovered that LittleCMS did not properly handle certain error conditions, resulting in a large memory leak. If a user or automated system were tricked into processing an image with malicious ICC tags, a remote attacker could cause a denial of service. Chris Evans discovered that LittleCMS contained multiple integer overflows. If a user or automated system were tricked into processing an image with malicious ICC tags, a remote attacker could crash applications linked against liblcms1, leading to a denial of service, or possibly execute arbitrary code with user privileges. Chris Evans discovered that LittleCMS did not properly perform bounds checking, leading to a buffer overflow. If a user or automated system were tricked into processing an image with malicious ICC tags, a remote attacker could execute arbitrary code with user privileges
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2009-0581
CVE-2009-0723
CVE-2009-0733
USN-744-1
USN-744-1
Platform(s):Ubuntu 6.06
Ubuntu 7.10
Ubuntu 8.04
Ubuntu 8.10
Product(s):lcms
Definition Synopsis
  • Release section
  • Ubuntu 7.10 is installed
  • AND Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is lpia
  • OR Installed architecture is powerpc
  • AND Packages section
  • liblcms1-dev DPKG is earlier than 1.16-5ubuntu3.2
  • OR python-liblcms DPKG is earlier than 1.16-5ubuntu3.2
  • OR liblcms-utils DPKG is earlier than 1.16-5ubuntu3.2
  • OR liblcms1 DPKG is earlier than 1.16-5ubuntu3.2
  • OR Release section
  • Ubuntu 8.04 is installed
  • AND Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is lpia
  • OR Installed architecture is powerpc
  • AND Packages section
  • liblcms1-dev DPKG is earlier than 1.16-7ubuntu1.2
  • OR python-liblcms DPKG is earlier than 1.16-7ubuntu1.2
  • OR liblcms-utils DPKG is earlier than 1.16-7ubuntu1.2
  • OR liblcms1 DPKG is earlier than 1.16-7ubuntu1.2
  • OR Release section
  • Ubuntu 6.06 is installed
  • AND Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is powerpc
  • AND Packages section
  • liblcms1-dev DPKG is earlier than 1.13-1ubuntu0.2
  • OR liblcms-utils DPKG is earlier than 1.13-1ubuntu0.2
  • OR liblcms1 DPKG is earlier than 1.13-1ubuntu0.2
  • OR Release section
  • Ubuntu 8.10 is installed
  • AND Supported architectures section
  • Installed architecture is sparc
  • OR Installed architecture is i386
  • OR Installed architecture is amd64
  • OR Installed architecture is lpia
  • OR Installed architecture is powerpc
  • AND Packages section
  • liblcms1-dev DPKG is earlier than 1.16-10ubuntu0.2
  • OR python-liblcms DPKG is earlier than 1.16-10ubuntu0.2
  • OR liblcms-utils DPKG is earlier than 1.16-10ubuntu0.2
  • OR liblcms1 DPKG is earlier than 1.16-10ubuntu0.2
  • BACK