Vulnerability Bulletins

DSA-3774 lcms2 - security update

   
Affected software Debian
 
Ibrahim M. El-Sayed discovered an out-of-bounds heap read vulnerabilityin the function Type_MLU_Read in lcms2, the Little CMS 2 colormanagement library, which can be triggered by an image with a speciallycrafted ICC profile and leading to a heap memory leak ordenial-of-service for applications using the lcms2 library.

More info:

https://www.debian.org/security/2017/dsa-3774