CVE-2012-4405 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4405): Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error.
+*argyllcms-1.4.0-r1 (01 Dec 2012) + + 01 Dec 2012; Pacho Ramos <pacho@gentoo.org> +argyllcms-1.4.0-r1.ebuild, + +files/argyllcms-1.4.0-CVE-2012-4405.patch: + Fix CVE-2012-4405 +
amd64 stable
x86 done, last arch!
Thanks, everyone. GLSA draft ready.
+ 14 Dec 2012; Justin Lecher <jlec@gentoo.org> -argyllcms-1.4.0.ebuild, + metadata.xml: + Drop vulnerable version, #437652 +
This issue was resolved and addressed in GLSA 201402-29 at http://security.gentoo.org/glsa/glsa-201402-29.xml by GLSA coordinator Sergey Popov (pinkbyte).