Bug#852627: lcms2: CVE-2016-10165: heap OOB read parsing crafted ICC profile

2017-01-25 Thread Salvatore Bonaccorso
Control: severity -1 grave Actually raising the severity to RC, think this should go into stretch and the patch is simple. Regards, Salvatore

Bug#852627: lcms2: CVE-2016-10165: heap OOB read parsing crafted ICC profile

2017-01-25 Thread Salvatore Bonaccorso
Source: lcms2 Version: 2.6-3 Severity: important Tags: upstream security patch Hi, the following vulnerability was published for lcms2. CVE-2016-10165[0]: heap OOB read parsing crafted ICC profile If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities &