Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 437652 (CVE-2012-4405) - <media-gfx/argyllcms-1.4.0-r1: Multiple integer underflows (CVE-2012-4405)
Summary: <media-gfx/argyllcms-1.4.0-r1: Multiple integer underflows (CVE-2012-4405)
Status: RESOLVED FIXED
Alias: CVE-2012-4405
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: http://nvd.nist.gov/nvd.cfm?cvename=C...
Whiteboard: B2 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-10-09 00:36 UTC by GLSAMaker/CVETool Bot
Modified: 2014-02-28 10:20 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2012-10-09 00:36:54 UTC
CVE-2012-4405 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4405):
  Multiple integer underflows in the icmLut_allocate function in International
  Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06
  and Argyll Color Management System, allow remote attackers to cause a denial
  of service (crash) and possibly execute arbitrary code via a crafted (1)
  PostScript or (2) PDF file with embedded images, which triggers a heap-based
  buffer overflow.  NOTE: this issue is also described as an array index
  error.
Comment 1 Pacho Ramos gentoo-dev 2012-12-01 08:45:12 UTC
+*argyllcms-1.4.0-r1 (01 Dec 2012)
+
+  01 Dec 2012; Pacho Ramos <pacho@gentoo.org> +argyllcms-1.4.0-r1.ebuild,
+  +files/argyllcms-1.4.0-CVE-2012-4405.patch:
+  Fix CVE-2012-4405
+
Comment 2 Agostino Sarubbo gentoo-dev 2012-12-01 21:27:04 UTC
amd64 stable
Comment 3 Andreas Schürch gentoo-dev 2012-12-03 11:08:53 UTC
x86 done, last arch!
Comment 4 Sean Amoss (RETIRED) gentoo-dev Security 2012-12-03 11:44:25 UTC
Thanks, everyone.

GLSA draft ready.
Comment 5 Justin Lecher (RETIRED) gentoo-dev 2012-12-14 08:31:28 UTC
+  14 Dec 2012; Justin Lecher <jlec@gentoo.org> -argyllcms-1.4.0.ebuild,
+  metadata.xml:
+  Drop vulnerable version, #437652
+
Comment 6 GLSAMaker/CVETool Bot gentoo-dev 2014-02-28 10:20:08 UTC
This issue was resolved and addressed in
 GLSA 201402-29 at http://security.gentoo.org/glsa/glsa-201402-29.xml
by GLSA coordinator Sergey Popov (pinkbyte).