CVE-2009-0584

icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 92%
VendorProductVersion
argyllcmscms
𝑥
≤ 1.0.3
ghostscriptghostscript
𝑥
≤ 8.64
ghostscriptghostscript
5.50
ghostscriptghostscript
7.05
ghostscriptghostscript
7.07
ghostscriptghostscript
8.0.1
ghostscriptghostscript
8.15
ghostscriptghostscript
8.15.2
ghostscriptghostscript
8.54
ghostscriptghostscript
8.56
ghostscriptghostscript
8.57
ghostscriptghostscript
8.60
ghostscriptghostscript
8.61
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
argyll
bullseye
2.0.1+repack-1.1
fixed
bookworm
2.3.1+repack-1.1
fixed
sid
3.1.0+repack-1.1
fixed
trixie
3.1.0+repack-1.1
fixed
ghostscript
bullseye
9.53.3~dfsg-7+deb11u7
fixed
bullseye (security)
9.53.3~dfsg-7+deb11u8
fixed
bookworm
10.0.0~dfsg-11+deb12u4
fixed
bookworm (security)
10.0.0~dfsg-11+deb12u5
fixed
sid
10.04.0~dfsg-1
fixed
trixie
10.04.0~dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ghostscript
intrepid
Fixed 8.63.dfsg.1-0ubuntu6.3
released
hardy
Fixed 8.61.dfsg.1-1ubuntu3.1
released
gutsy
Fixed 8.61.dfsg.1~svn8187-0ubuntu3.5
released
dapper
dne
gs-gpl
intrepid
dne
hardy
dne
gutsy
dne
dapper
Fixed 8.15-4ubuntu3.2
released
Common Weakness Enumeration
References