|
|
>> Mandriva Security Update Fixes Little CMS Buffer Overflow Vulnerability
|
Title : Mandriva Security Update Fixes Little CMS Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-4107 CVE ID : CVE-2007-2741
Rated as : Moderate Risk 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-07
|
A vulnerability has been identified in Mandriva, which could be exploited by attackers to cause a denial of service or execute arbitrary code. This issue is caused by an error in Little CMS (lcms). For additional information, see : VUPEN/ADV-2007-1837
Affected Products
Mandriva Corporate 3.0
Mandriva Corporate 4.0
Solution
Upgrade the affected packages :
Corporate 3.0:
67235f6fbaa2e362cc0c1d52649d18d3 corporate/3.0/i586/liblcms1-1.10-1.1.C30mdk.i586.rpm
805fa6864cf88a13b941ec4e413c71e0 corporate/3.0/i586/liblcms1-devel-1.10-1.1.C30mdk.i586.rpm
293cca953384a2f3bac3cc2ea65b1b55 corporate/3.0/SRPMS/liblcms-1.10-1.1.C30mdk.src.rpm
Corporate 3.0/X86_64:
78a9e7f2ea86ff138e07237c3b5d5bbe corporate/3.0/x86_64/lib64lcms1-1.10-1.1.C30mdk.x86_64.rpm
d5e8741839d23244b7cb357ef3cf8dbf corporate/3.0/x86_64/lib64lcms1-devel-1.10-1.1.C30mdk.x86_64.rpm
293cca953384a2f3bac3cc2ea65b1b55 corporate/3.0/SRPMS/liblcms-1.10-1.1.C30mdk.src.rpm
Corporate 4.0:
005f430298518600444476df0864ae5d corporate/4.0/i586/liblcms1-1.14-1.1.20060mlcs4.i586.rpm
9ddc51c13d7b905cc519b1e01923001d corporate/4.0/i586/liblcms1-devel-1.14-1.1.20060mlcs4.i586.rpm
2bea4f9e697ab0ff649e626f4d66681c corporate/4.0/SRPMS/liblcms-1.14-1.1.20060mlcs4.src.rpm
Corporate 4.0/X86_64:
79be0e773bb6dd1736e5249801dedd36 corporate/4.0/x86_64/lib64lcms1-1.14-1.1.20060mlcs4.x86_64.rpm
f4b498d695b67bdb99598c8d752c9176 corporate/4.0/x86_64/lib64lcms1-devel-1.14-1.1.20060mlcs4.x86_64.rpm
2bea4f9e697ab0ff649e626f4d66681c corporate/4.0/SRPMS/liblcms-1.14-1.1.20060mlcs4.src.rpm
References
http://www.vupen.com/english/advisories/2007/4107 http://archives.mandrivalinux.com/security-announce/2007-12/msg00006.php
ChangeLog
2007-12-07 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|