Bug#728208: liblcms1: CVE-2013-4160 - lcms can be made to crash

2014-03-27 Thread Tobias Frost
Package: liblcms1 Tags: +patch Followup-For: Bug #728208 -BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hi, I analyzed the bugfix [1] upstream applied to fix this CVE in lcms-2, and backported the fix. The code diverged very much and some of the issues are not in lcms1, therefore the is the

Bug#728208: liblcms1: CVE-2013-4160 - lcms can be made to crash

2013-10-29 Thread Arne Wichmann
Package: liblcms1 Version: 1.19.dfsg-1.2 Severity: important Tags: security Dear Maintainer, CVE-2013-4160 also applies to lcms. cu AW -- System Information: Debian Release: jessie/sid APT prefers testing APT policy: (500, 'testing'), (500, 'stable'), (50, 'unstable'), (40,