Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade hpijsUpgrade ghostscript-gtkUpgrade ghostscriptUpgrade ghostscript-devel | Dec 1, 2016 | Apr 14, 2009 |
| Debian | — | Upgrade ghostscriptUpgrade argyll | Jul 30, 2024 | Apr 14, 2009 |
| Gentoo Linux | — | Upgrade app-text/ghostscript-gpl. | Oct 30, 2017 | Apr 14, 2009 |
| Oracle_linux | — | Upgrade ghostscriptUpgrade ghostscript-develUpgrade ghostscript-gtk | Oct 16, 2024 | Apr 14, 2009 |
| Suse | — | Upgrade libgimpprintUpgrade ghostscript-x11Upgrade libgimpprint-develUpgrade ghostscript-fonts-otherUpgrade ghostscript-ijs-develUpgrade ghostscript-develUpgrade ghostscript-omniUpgrade ghostscript-fonts-stdUpgrade ghostscript-libraryUpgrade ghostscript-fonts-rus | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libgs8Upgrade gs-gplUpgrade gs-esp | Nov 8, 2024 | Apr 14, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub