icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade ghostscript-develUpgrade hpijsUpgrade ghostscript | Dec 1, 2016 | Mar 23, 2009 |
| Debian | — | Upgrade ghostscriptUpgrade argyll | Jul 30, 2024 | Mar 23, 2009 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 24, 2013 |
| Gentoo Linux | — | Upgrade app-text/ghostscript-esp.Upgrade app-text/ghostscript-gpl.Upgrade app-text/ghostscript-gnu. | Oct 30, 2017 | Mar 23, 2009 |
| Oracle_linux | — | Upgrade ghostscriptUpgrade ghostscript-develUpgrade ghostscript-gtk | Oct 16, 2024 | Mar 23, 2009 |
| Suse | — | Upgrade ghostscript-fonts-otherUpgrade ghostscript-fonts-stdUpgrade ghostscript-omniUpgrade ghostscript-libraryUpgrade ghostscript-x11Upgrade libgimpprintUpgrade ghostscript-ijs-develUpgrade ghostscript-develUpgrade libgimpprint-develUpgrade ghostscript-fonts-rus | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade gs-gplUpgrade gs-espUpgrade libgs8 | Nov 8, 2024 | Mar 23, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub