Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Daily Reviews Summary 02/09/12
· 3 Advanced Tips & Tricks For Using Windows Explorer
· MySQL 5.5.20 for Debian 6
· How to Install Screenlets for Desktop Widgets in Linux Mint 12
· Microsoft, Google, and Apple talk up "fair and reasonable" patent license fees
· Latest Windows 8 and Windows 8 Server build numbers revealed
· 3 CentOS Updates
· 3 RHEL Updates
· European Apple resellers say lack of inventory is putting them out of business
· Latest Windows 8 Consumer Preview build number: 8225?

Upcoming News
· [security-announce] openSUSE-SU-2012:0234-1: important: MozillaFirefox: Version 10
· [security-announce] openSUSE-SU-2012:0236-1: important: kernel: security and bugfix update.
· [security-announce] openSUSE-SU-2012:0237-1: important: VUL-0: nginx: heap overflow
· [security-announce] openSUSE-SU-2012:0227-1: important: xorg-x11-server
· [security-announce] openSUSE-SU-2012:0039-2: important: MozillaFirefox
· [security-announce] SUSE-SU-2012:0221-1: important: Security update for Mozilla Firefox
· [security-announce] openSUSE-SU-2012:0206-1: important: kernel: security and bugfix update.
· [security-announce] openSUSE-SU-2012:0208-1: important: tomcat6: Fix multiple weaknesses in HTTP DIGESTS
· [security-announce] SUSE-SU-2012:0198-1: important: Security update for Mozilla XULrunner
· [RHSA-2012:0107-01] Important: kernel security and bug fix update

Linux Compatibility
· XPS L502X
· Slim Portable DVD Writer GP10
· AverTV Volar Green HD
· Dell Latitude E6420
· Canon CanoScan FB 636U
· Logitech QuickCam Pro 4000
· GeForce 7300 GT
· Umax Astra 4500 USB Scanner
· Photosmart Pro B9180
· kingston DataTraveler DTI/16GB

New Forum Topics
· Directx
by: Rajoo
on: 2012-02-06 21:29
0 replies, 113 views

· Code: Bad EIP Value
by: megatouchguy
on: 2012-01-28 06:27
0 replies, 355 views

· XP Pro crashes on start up
by: javien
on: 2012-01-17 12:38
6 replies, 2030 views

· Lan Wireless Access To Shared Folders Problem
by: MinusZero
on: 2012-01-09 06:45
2 replies, 2212 views

· Motherboard glitch
by: danleff
on: 2012-01-08 12:03
3 replies, 655 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » October 2008 » USN-652-1: LittleCMS vulnerability

USN-652-1: LittleCMS vulnerability

Posted by Bob on: 10/14/2008 06:30 PM [ Print | 0 comment(s) ]

A new LittleCMS vulnerability update is available for Ubuntu Linux. Here the announcement:




Ubuntu Security Notice USN-652-1 October 14, 2008
lcms vulnerability
CVE-2007-2741
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the
following package versions:

Ubuntu 6.06 LTS:
liblcms1 1.13-1ubuntu0.1

In general, a standard system upgrade is sufficient to effect the
necessary changes.

Details follow:

Chris Evans discovered that certain ICC operations in lcms were not
correctly bounds-checked. If a user or automated system were tricked
into processing an image with malicious ICC tags, a remote attacker could
crash applications linked against liblcms1, leading to a denial of service,
or possibly execute arbitrary code with user privileges.


Updated packages for Ubuntu 6.06 LTS:

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/l/lcms/lcms_1.13-1ubuntu0.1.diff.gz
Size/MD5: 13103 4617c440a02960e1f962a88c1c21a9cc
http://security.ubuntu.com/ubuntu/pool/main/l/lcms/lcms_1.13-1ubuntu0.1.dsc
Size/MD5: 685 507f6385801f19716737a5089d33116d
http://security.ubuntu.com/ubuntu/pool/main/l/lcms/lcms_1.13.orig.tar.gz
Size/MD5: 585735 e627f43bbbd238895502402d942a6cfd

amd64 architecture (Athlon64, Opteron, EM64T Xeon):

http://security.ubuntu.com/ubuntu/pool/main/l/lcms/liblcms1-dev_1.13-1ubuntu0.1_amd64.deb
Size/MD5: 136682 f085666f76c9bf1a53942baa18b8e052
http://security.ubuntu.com/ubuntu/pool/main/l/lcms/liblcms1_1.13-1ubuntu0.1_amd64.deb
Size/MD5: 129070 e50c4bfb5b0e32ec7f3da1ce9e1ee21f
http://security.ubuntu.com/ubuntu/pool/universe/l/lcms/liblcms-utils_1.13-1ubuntu0.1_amd64.deb
Size/MD5: 40296 5c58c601e0d9802394cf25b33319b2c9

i386 architecture (x86 compatible Intel/AMD):

http://security.ubuntu.com/ubuntu/pool/main/l/lcms/liblcms1-dev_1.13-1ubuntu0.1_i386.deb
Size/MD5: 123518 fd6961be0da7aaf2e2dcb8257d3787da
http://security.ubuntu.com/ubuntu/pool/main/l/lcms/liblcms1_1.13-1ubuntu0.1_i386.deb
Size/MD5: 118222 86dcc1004a11232740c2d6d6903f02a4
http://security.ubuntu.com/ubuntu/pool/universe/l/lcms/liblcms-utils_1.13-1ubuntu0.1_i386.deb
Size/MD5: 37112 d4ffa7a920a4e4aba5f8d197d1ad14f0

powerpc architecture (Apple Macintosh G3/G4/G5):

http://security.ubuntu.com/ubuntu/pool/main/l/lcms/liblcms1-dev_1.13-1ubuntu0.1_powerpc.deb
Size/MD5: 130806 3da85714083d3d4f1252ae0b1b1fe6e3
http://security.ubuntu.com/ubuntu/pool/main/l/lcms/liblcms1_1.13-1ubuntu0.1_powerpc.deb
Size/MD5: 131834 38aba2a645449be653dd11be439afcce
http://security.ubuntu.com/ubuntu/pool/universe/l/lcms/liblcms-utils_1.13-1ubuntu0.1_powerpc.deb
Size/MD5: 44136 04799ca5393e6acc70592f648b6b846a

sparc architecture (Sun SPARC/UltraSPARC):

http://security.ubuntu.com/ubuntu/pool/main/l/lcms/liblcms1-dev_1.13-1ubuntu0.1_sparc.deb
Size/MD5: 133960 ab907a81dcb99819e9d125b76a34742c
http://security.ubuntu.com/ubuntu/pool/main/l/lcms/liblcms1_1.13-1ubuntu0.1_sparc.deb
Size/MD5: 124964 42864911b8a3f680a7aae8d28701a6c1
http://security.ubuntu.com/ubuntu/pool/universe/l/lcms/liblcms-utils_1.13-1ubuntu0.1_sparc.deb
Size/MD5: 38498 5d040f607c0ec6d411349b0d27b52e73


--48TaNjbzBVislYPb
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Kees Cook lt;kees@outflux.netgt;

iEYEARECAAYFAkj01bcACgkQH/9LqRcGPm3TcACghKI6Y4hKQm5RvJ9G2QlHxuI8
mnsAn3hmwtfSw7DPin2n1ITAcdgB4UpT
=0fkh
-----END PGP SIGNATURE-----


Bookmark and Share

« Carbon Copy Cloner 3.1.2 · USN-653-1: D-Bus vulnerabilities »

Linux Compatible » News » October 2008 » USN-652-1: LittleCMS vulnerability
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2011 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition