* CVE-2018-16435 Description: "Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile."
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=32549db87950e4b96ecb107d9e4389006b94d831 commit 32549db87950e4b96ecb107d9e4389006b94d831 Author: John Helmert III <jchelmert3@posteo.net> AuthorDate: 2020-12-27 09:28:00 +0000 Commit: Andreas Sturmlechner <asturm@gentoo.org> CommitDate: 2020-12-27 09:46:37 +0000 media-libs/lcms: security cleanup (drop <2.11) Bug: https://bugs.gentoo.org/761418 Package-Manager: Portage-3.0.12, Repoman-3.0.2 Signed-off-by: John Helmert III <jchelmert3@posteo.net> Closes: https://github.com/gentoo/gentoo/pull/18829 Signed-off-by: Andreas Sturmlechner <asturm@gentoo.org> media-libs/lcms/Manifest | 2 -- media-libs/lcms/files/lcms-2.9-BE-test.patch | 54 ---------------------------- media-libs/lcms/lcms-2.10.ebuild | 49 ------------------------- media-libs/lcms/lcms-2.9.ebuild | 52 --------------------------- 4 files changed, 157 deletions(-)
Needs vote
New GLSA request filed.
This issue was resolved and addressed in GLSA 202105-18 at https://security.gentoo.org/glsa/202105-18 by GLSA coordinator Thomas Deutschmann (whissi).