[Bluewhite64 Linux Security] lcms [BW64SA:20090326-01]

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


[Bluewhite64 Linux Security] lcms [BW64SA:20090326-01]


New lcms packages are available for Bluewhite64 11.0, 12.0, 12.1, 12.2, and -current to
fix security issues.

More details about the issues may be found in the Common Vulnerabilities and Exposures
(CVE) database:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0581
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0723
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0733



Here are the details from the Bluewhite64 12.2 ChangeLog:
- ----------------------------------------------------------
PATCHES/packages/lcms-1.18-x86_64-1.tgz: Upgraded to lcms-1.18.
This update fixes security issues discovered in LittleCMS by Chris Evans.
These flaws could cause program crashes (denial of service) or the execution
of arbitrary code as the user of the lcms-linked program.
For more information, see:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0581
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0723
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0733
[*** Security fix ***]




Download the new packages from:
- --------------------------------
For Bluewhite64 Linux 11.0:
http://data.bluewhite64.com/bluewhite64-11.1/patches/packages/lcms-1.18-x86_64-1.tgz

For Bluewhite64 Linux 12.0:
http://data.bluewhite64.com/bluewhite64-12.0/patches/packages/lcms-1.18-x86_64-1.tgz

For Bluewhite64 Linux 12.1:
http://data.bluewhite64.com/bluewhite64-12.1/patches/packages/lcms-1.18-x86_64-1.tgz

For Bluewhite64 Linux 12.2:
http://data.bluewhite64.com/bluewhite64-12.2/patches/packages/lcms-1.18-x86_64-1.tgz

For Bluewhite64 Linux -current:
http://data.bluewhite64.com/bluewhite64-current/bluewhite64/l/lcms-1.18-x86_64-1.tgz

Also, please see the "Get Bluewhite64" section on http://www.bluewhite64.com for
additional mirror sites near you.




MD5 signatures:
- ----------------
Bluewhite64 11.0 package:
57fb95cb06309703fb332c58b34227b8 lcms-1.18-x86_64-1.tgz

Bluewhite64 12.0 package:
06864aedf7e89abe5ba58480463de384 lcms-1.18-x86_64-1.tgz

Bluewhite64 12.1 package:
f72f8f8ebe6f4c10acb24425f4d66059 lcms-1.18-x86_64-1.tgz

Bluewhite64 12.2 package:
5740d05c240ee787e0fe2a7b5c2634ba lcms-1.18-x86_64-1.tgz

Bluewhite64 -current package:
738cd1e4f0e12f701da6294eacac90bc lcms-1.18-x86_64-1.tgz



Installation instructions:
- ----------------------------
Upgrade the package as root:
# upgradepkg lcms-1.18-x86_64-1.tgz


- ---
Bluewhite64 Linux Security Team
http://bluewhite64.com/gpg-key

security©bluewhite64.com



- ------------------------------------------------------
To leave the bluewhite64-security mailing list:
Send a blank email to

bluewhite64-security-unsubscribe©bluewhite64.com

You will get a confirmation message back containing
instructions to complete the process.

Please do not reply to this email address.
- ------------------------------------------------------


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)

iEYEARECAAYFAknLfkgACgkQpTOsxuDdlY6NRwCeIvoFYZJ0FhDOorsqoeO3Mg0O
pTUAmgLf8xHNKHME/6Ie1XsX+BSpq+Y/
=QVWa
-----END PGP SIGNATURE-----