Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.
{ "binaries": [ { "binary_name": "chromium-browser", "binary_version": "69.0.3497.81-0ubuntu0.16.04.1" }, { "binary_name": "chromium-browser-l10n", "binary_version": "69.0.3497.81-0ubuntu0.16.04.1" }, { "binary_name": "chromium-chromedriver", "binary_version": "69.0.3497.81-0ubuntu0.16.04.1" }, { "binary_name": "chromium-codecs-ffmpeg", "binary_version": "69.0.3497.81-0ubuntu0.16.04.1" }, { "binary_name": "chromium-codecs-ffmpeg-extra", "binary_version": "69.0.3497.81-0ubuntu0.16.04.1" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_name": "liboxideqt-qmlplugin", "binary_version": "1.21.5-0ubuntu0.16.04.1" }, { "binary_name": "liboxideqtcore-dev", "binary_version": "1.21.5-0ubuntu0.16.04.1" }, { "binary_name": "liboxideqtcore0", "binary_version": "1.21.5-0ubuntu0.16.04.1" }, { "binary_name": "liboxideqtquick-dev", "binary_version": "1.21.5-0ubuntu0.16.04.1" }, { "binary_name": "liboxideqtquick0", "binary_version": "1.21.5-0ubuntu0.16.04.1" }, { "binary_name": "oxideqt-codecs", "binary_version": "1.21.5-0ubuntu0.16.04.1" }, { "binary_name": "oxideqt-codecs-extra", "binary_version": "1.21.5-0ubuntu0.16.04.1" } ] }
{ "binaries": [ { "binary_name": "chromium-browser", "binary_version": "69.0.3497.81-0ubuntu0.18.04.1" }, { "binary_name": "chromium-browser-l10n", "binary_version": "69.0.3497.81-0ubuntu0.18.04.1" }, { "binary_name": "chromium-chromedriver", "binary_version": "69.0.3497.81-0ubuntu0.18.04.1" }, { "binary_name": "chromium-codecs-ffmpeg", "binary_version": "69.0.3497.81-0ubuntu0.18.04.1" }, { "binary_name": "chromium-codecs-ffmpeg-extra", "binary_version": "69.0.3497.81-0ubuntu0.18.04.1" } ], "availability": "No subscription required" }