CVE-2018-16435
Publication date 3 September 2018
Last updated 25 August 2025
Ubuntu priority
Medium
Description
Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| chromium-browser | 19.04 disco |
Fixed 69.0.3497.81-0ubuntu1
|
| 18.10 cosmic |
Fixed 69.0.3497.81-0ubuntu1
|
|
| 18.04 LTS bionic |
Fixed 69.0.3497.81-0ubuntu0.18.04.1
|
|
| 16.04 LTS xenial |
Fixed 69.0.3497.81-0ubuntu0.16.04.1
|
|
| 14.04 LTS trusty | Not in release | |
| lcms | 19.04 disco | Not in release |
| 18.10 cosmic | Not in release | |
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Not in release | |
| 14.04 LTS trusty | Not in release | |
| lcms2 | 19.04 disco |
Fixed 2.9-3
|
| 18.10 cosmic |
Fixed 2.9-3
|
|
| 18.04 LTS bionic |
Fixed 2.9-1ubuntu0.1
|
|
| 16.04 LTS xenial |
Fixed 2.6-3ubuntu2.1
|
|
| 14.04 LTS trusty |
Fixed 2.5-0ubuntu4.2
|
|
| oxide-qt | 19.04 disco | Not in release |
| 18.10 cosmic | Not in release | |
| 18.04 LTS bionic | Not in release | |
| 16.04 LTS xenial | Ignored end of standard support | |
| 14.04 LTS trusty | Not in release |
Patch details
For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?
| Package | Patch details |
|---|---|
| lcms |
|
| lcms2 |
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score 5.5 · Medium
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
References
Related Ubuntu Security Notices (USN)
- USN-3770-2
- Little CMS vulnerabilities
- 20 September 2018
- USN-3770-1
- Little CMS vulnerabilities
- 20 September 2018