Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ghostscript | Aug 30, 2017 | Sep 18, 2012 |
| Centos_linux | — | Upgrade ghostscript-docUpgrade ghostscriptUpgrade ghostscript-gtkUpgrade ghostscript-devel | Dec 1, 2016 | Sep 18, 2012 |
| Debian | — | Upgrade argyllUpgrade ghostscript | Jul 30, 2024 | Sep 18, 2012 |
| Gentoo Linux | — | Upgrade media-gfx/argyllcms.Upgrade app-text/ghostscript-gpl. | Oct 30, 2017 | Sep 18, 2012 |
| Oracle_linux | — | Upgrade ghostscript-develUpgrade ghostscript-docUpgrade ghostscript-gtkUpgrade ghostscript | Oct 16, 2024 | Sep 18, 2012 |
| Suse | — | Upgrade ghostscript-libraryUpgrade ghostscript-fonts-rusUpgrade ghostscript-fonts-otherUpgrade ghostscript-omniUpgrade ghostscript-ijs-develUpgrade ghostscript-develUpgrade ghostscript-x11Upgrade libgimpprintUpgrade libgimpprint-develUpgrade ghostscript-fonts-std | Feb 17, 2015 | Jun 28, 2013 |
| Ubuntu | — | Upgrade libgs8 | Nov 8, 2024 | Sep 18, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub