Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade ghostscript-develUpgrade hpijsUpgrade ghostscript | Dec 1, 2016 | Mar 23, 2009 |
| Debian | — | Upgrade argyllUpgrade ghostscript | Jul 30, 2024 | Mar 23, 2009 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 24, 2013 |
| Gentoo Linux | — | Upgrade app-text/ghostscript-gpl.Upgrade app-text/ghostscript-esp.Upgrade app-text/ghostscript-gnu. | Oct 30, 2017 | Mar 23, 2009 |
| Oracle_linux | — | Upgrade ghostscript-gtkUpgrade ghostscript-develUpgrade ghostscript | Oct 16, 2024 | Mar 23, 2009 |
| Suse | — | Upgrade libgimpprint-develUpgrade libgimpprintUpgrade ghostscript-develUpgrade ghostscript-omniUpgrade ghostscript-fonts-rusUpgrade ghostscript-libraryUpgrade ghostscript-fonts-otherUpgrade ghostscript-ijs-develUpgrade ghostscript-fonts-stdUpgrade ghostscript-x11 | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libgs8Upgrade gs-gplUpgrade gs-esp | Nov 8, 2024 | Mar 23, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub