CVE-2009-0583

EUVD-2009-0586
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
Affected Products (NVD)
VendorProductVersion
ghostscriptghostscript
𝑥
≤ 8.64
ghostscriptghostscript
5.50
ghostscriptghostscript
7.05
ghostscriptghostscript
7.07
ghostscriptghostscript
8.0.1
ghostscriptghostscript
8.15
ghostscriptghostscript
8.15.2
ghostscriptghostscript
8.54
ghostscriptghostscript
8.56
ghostscriptghostscript
8.57
ghostscriptghostscript
8.61
ghostscriptghostscript
8.62
ghostscriptghostscript
8.63
argyllcmsargyllcms
𝑥
≤ 1.0.3
argyllcmsargyllcms
0.1.0
argyllcmsargyllcms
0.2.0
argyllcmsargyllcms
0.2.1
argyllcmsargyllcms
0.2.2
argyllcmsargyllcms
0.3.0
argyllcmsargyllcms
0.6.0
argyllcmsargyllcms
0.7.0:beta_8
argyllcmsargyllcms
1.0.0
argyllcmsargyllcms
1.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
argyll
bookworm
2.3.1+repack-1.1
fixed
bullseye
2.0.1+repack-1.1
fixed
sid
3.1.0+repack-1.1
fixed
trixie
3.1.0+repack-1.1
fixed
ghostscript
bookworm
10.0.0~dfsg-11+deb12u4
fixed
bookworm (security)
10.0.0~dfsg-11+deb12u5
fixed
bullseye
9.53.3~dfsg-7+deb11u7
fixed
bullseye (security)
9.53.3~dfsg-7+deb11u8
fixed
sid
10.04.0~dfsg-1
fixed
trixie
10.04.0~dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ghostscript
dapper
dne
gutsy
Fixed 8.61.dfsg.1~svn8187-0ubuntu3.5
released
hardy
Fixed 8.61.dfsg.1-1ubuntu3.1
released
intrepid
Fixed 8.63.dfsg.1-0ubuntu6.3
released
gs-gpl
dapper
Fixed 8.15-4ubuntu3.2
released
gutsy
dne
hardy
dne
intrepid
dne
References