Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade ghostscriptUpgrade ghostscript-develUpgrade hpijs | Dec 1, 2016 | Mar 23, 2009 |
| Debian | — | Upgrade argyllUpgrade ghostscript | Jul 30, 2024 | Mar 23, 2009 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 24, 2013 |
| Gentoo Linux | — | Upgrade app-text/ghostscript-gnu.Upgrade app-text/ghostscript-gpl.Upgrade app-text/ghostscript-esp. | Oct 30, 2017 | Mar 23, 2009 |
| Oracle_linux | — | Upgrade ghostscript-develUpgrade ghostscriptUpgrade ghostscript-gtk | Oct 16, 2024 | Mar 23, 2009 |
| Suse | — | Upgrade ghostscript-fonts-rusUpgrade ghostscript-fonts-otherUpgrade libgimpprintUpgrade ghostscript-x11Upgrade ghostscript-ijs-develUpgrade ghostscript-develUpgrade ghostscript-omniUpgrade ghostscript-libraryUpgrade ghostscript-fonts-stdUpgrade libgimpprint-devel | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade gs-espUpgrade gs-gplUpgrade libgs8 | Nov 8, 2024 | Mar 23, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub