ArgyllCMS: User-assisted execution of arbitrary code
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201206-04 / argyllcms |
| Release Date |
June 18, 2012 |
| Latest Revision |
June 18, 2012: 1 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| media-gfx/argyllcms |
<
1.4.0 |
>=
1.4.0 |
All supported architectures
|
Related bugreports:
#416781
Synopsis
A vulnerability has been found in ArgyllCMS which could allow
attackers to execute arbitrary code.
2.
Impact Information
Background
ArgyllCMS is an ICC compatible color management system that supports
accurate ICC profile creation for scanners, cameras and film recorders.
Description
ArgyllCMS does not properly handle ICC profiles causing a use-after-free
vulnerability.
Impact
A remote attacker could entice a user to open a specially crafted image
file using ArgyllCMS, possibly resulting in execution of arbitrary code
with the privileges of the process, or a Denial of Service condition.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All argyllcms users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=media-gfx/argyllcms-1.4.0"
|
4.
References
|