Debian Security Advisory

DLA-1496-1 lcms2 -- LTS security update

Date Reported:
06 Sep 2018
Affected Packages:
lcms2
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2018-16435.
More information:

It was discovered that there was an integer overflow vulnerability in the Little CMS 2 colour management library. A specially-crafted input file could lead to a heap-based buffer overflow.

For Debian 8 Jessie, this issue has been fixed in lcms2 version 2.6-3+deb8u2.

We recommend that you upgrade your lcms2 packages.