All errata/sisyphus/ALT-PU-2020-4298-1
ALT-PU-2020-4298-1

Package update liblcms2 in branch sisyphus

Version2.11-alt1
Published2020-06-16
Max severityHIGH
Severity:

Closed issues (1)

CVE-2016-10165
HIGH7.1

The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.

Published: 2017-02-03Modified: 2025-04-20
CVSS 2.0MEDIUM 5.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:N/A:P
CVSS 3.xHIGH 7.1
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
References