SuSE 11.3 Security Update : lcms2 (SAT Patch Number 8091)

This script is Copyright (C) 2013 Tenable Network Security, Inc.


Synopsis :

The remote SuSE 11 host is missing one or more security updates.

Description :

lcms2 has been updated to the version 2.5 which is a maintenance
release to fix various security and other bugs.

- User defined parametric curves can now be saved in ICC
profiles.

- RGB profiles using same tone curves for several channels
are storing now only one copy of the curve

- update black point detection algorithm to reflect ICC
changes

- Added new cmsPlugInTHR() and fixed some race conditions

- Added error descriptions on cmsSmoothToneCurve

- Several improvements in cgats parser.

- Fixed devicelink generation for 8 bits

- Added a reference for Mac MLU tag

- Added a way to read the profile creator from header

- Added identity curves support for write V2 LUT

- Added TIFF Lab16 handling on tifficc

- Fixed a bug in parametric curves

- Rendering intent used when creating the transform is now
propagated to profile header in cmsTransform2Devicelink.

- Transform2Devicelink now keeps white point when guessing
deviceclass is enabled

- Added some checks for non-happy path, mostly failing
mallocs (bnc#826097). For further changes please see the
ChangeLog in the RPM.

See also :

https://bugzilla.novell.com/show_bug.cgi?id=826097

Solution :

Apply SAT patch number 8091.

Risk factor :

High

Family: SuSE Local Security Checks

Nessus Plugin ID: 69054 ()

Bugtraq ID:

CVE ID: