CVE-2009-0583

Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 87%
VendorProductVersion
ghostscriptghostscript
𝑥
≤ 8.64
ghostscriptghostscript
5.50
ghostscriptghostscript
7.05
ghostscriptghostscript
7.07
ghostscriptghostscript
8.0.1
ghostscriptghostscript
8.15
ghostscriptghostscript
8.15.2
ghostscriptghostscript
8.54
ghostscriptghostscript
8.56
ghostscriptghostscript
8.57
ghostscriptghostscript
8.61
ghostscriptghostscript
8.62
ghostscriptghostscript
8.63
argyllcmsargyllcms
𝑥
≤ 1.0.3
argyllcmsargyllcms
0.1.0
argyllcmsargyllcms
0.2.0
argyllcmsargyllcms
0.2.1
argyllcmsargyllcms
0.2.2
argyllcmsargyllcms
0.3.0
argyllcmsargyllcms
0.6.0
argyllcmsargyllcms
0.7.0:beta_8
argyllcmsargyllcms
1.0.0
argyllcmsargyllcms
1.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
argyll
bullseye
2.0.1+repack-1.1
fixed
bookworm
2.3.1+repack-1.1
fixed
sid
3.1.0+repack-1.1
fixed
trixie
3.1.0+repack-1.1
fixed
ghostscript
bullseye
9.53.3~dfsg-7+deb11u7
fixed
bullseye (security)
9.53.3~dfsg-7+deb11u8
fixed
bookworm
10.0.0~dfsg-11+deb12u4
fixed
bookworm (security)
10.0.0~dfsg-11+deb12u5
fixed
sid
10.04.0~dfsg-1
fixed
trixie
10.04.0~dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ghostscript
intrepid
Fixed 8.63.dfsg.1-0ubuntu6.3
released
hardy
Fixed 8.61.dfsg.1-1ubuntu3.1
released
gutsy
Fixed 8.61.dfsg.1~svn8187-0ubuntu3.5
released
dapper
dne
gs-gpl
intrepid
dne
hardy
dne
gutsy
dne
dapper
Fixed 8.15-4ubuntu3.2
released
References