USN-2961-1: Little CMS vulnerability
USN-2961-1: Little CMS vulnerability Ubuntu Security Notice USN-2961-1 4th May, 2016 lcms2 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Applications using the Little CMS library could be made to crash or run programs as your login if it opened a specially crafted file. Software description lcms2 – Little CMS color management library Details It was discovered that a double free() could occur when the intent handlingcode in the Little CMS library detected an error. An attacker could usethis to specially craft a file that caused an application using the LittleCMS library to crash or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 14.04 LTS: liblcms2-utils 2.5-0ubuntu4.1 liblcms2-2 2.5-0ubuntu4.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After [ more… ]