Home
Reading
Searching
Subscribe
Sponsors
Statistics
Posting
Contact
Spam
Lists
Links
About
Hosting
Filtering
Features Download
Marketing
Archives
FAQ
Blog
 
Gmane
From: <updates <at> fedoraproject.org>
Subject: [SECURITY] Fedora 10 Update: argyllcms-1.0.3-4.fc10
Newsgroups: gmane.linux.redhat.fedora.package.announce
Date: Thursday 9th April 2009 16:08:40 UTC (over 7 years ago)
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-3435
2009-04-09 15:24:33
--------------------------------------------------------------------------------

Name        : argyllcms
Product     : Fedora 10
Version     : 1.0.3
Release     : 4.fc10
URL         : http://www.argyllcms.com/
Summary     : ICC compatible color management system
Description :
The Argyll color management system supports accurate ICC profile creation
for
scanners, CMYK printers, film recorders and calibration and profiling of
displays.

Spectral sample data is supported, allowing a selection of illuminants
observer
types, and paper fluorescent whitener additive compensation. Profiles can
also
incorporate source specific gamut mappings for perceptual and saturation
intents. Gamut mapping and profile linking uses the CIECAM02 appearance
model,
a unique gamut mapping algorithm, and a wide selection of rendering
intents. It
also includes code for the fastest portable 8 bit raster color conversion
engine available anywhere, as well as support for fast, fully accurate 16
bit
conversion. Device color gamuts can also be viewed and compared using a
VRML
viewer.

--------------------------------------------------------------------------------
Update Information:

Multiple integer overflows and multiple insufficient upper-bounds checks on
certain variable sizes were originally discovered in the Ghostscript's
International Color Consortium Format Library (icclib). It was found,  the
original patch, addressing this issue was incomplete.
--------------------------------------------------------------------------------
ChangeLog:

* Wed Apr  8 2009 Jon Ciesla  - 1.0.3-4
- Patch for ICC library CVE-2009-0792.
* Mon Mar 23 2009 Jon Ciesla  - 1.0.3-3
- Patch for ICC library CVE-2009-{0583, 0584} by Tim Waugh.
* Mon Feb 23 2009 Fedora Release Engineering
 - 1.0.3-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #491853 - CVE-2009-0792 ghostscript, argyllcms: Incomplete fix
for CVE-2009-0583
        https://bugzilla.redhat.com/show_bug.cgi?id=491853
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update argyllcms' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on
the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
--------------------------------------------------------------------------------
 
CD: 3ms