icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade ghostscriptUpgrade ghostscript-develUpgrade hpijs | Dec 1, 2016 | Mar 23, 2009 |
| Debian | — | Upgrade ghostscriptUpgrade argyll | Jul 30, 2024 | Mar 23, 2009 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Mar 24, 2013 |
| Gentoo Linux | — | Upgrade app-text/ghostscript-gpl.Upgrade app-text/ghostscript-gnu.Upgrade app-text/ghostscript-esp. | Oct 30, 2017 | Mar 23, 2009 |
| Oracle_linux | — | Upgrade ghostscriptUpgrade ghostscript-develUpgrade ghostscript-gtk | Oct 16, 2024 | Mar 23, 2009 |
| Suse | — | Upgrade libgimpprint-develUpgrade ghostscript-fonts-rusUpgrade ghostscript-develUpgrade libgimpprintUpgrade ghostscript-fonts-otherUpgrade ghostscript-libraryUpgrade ghostscript-omniUpgrade ghostscript-ijs-develUpgrade ghostscript-x11Upgrade ghostscript-fonts-std | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade gs-espUpgrade libgs8Upgrade gs-gpl | Nov 8, 2024 | Mar 23, 2009 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub