CVE-2009-0792

EUVD-2009-0790
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.  NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
Affected Products (NVD)
VendorProductVersion
ghostscriptghostscript
𝑥
≤ 8.64
ghostscriptghostscript
5.50
ghostscriptghostscript
7.05
ghostscriptghostscript
7.07
ghostscriptghostscript
8.0.1
ghostscriptghostscript
8.15
ghostscriptghostscript
8.15.2
ghostscriptghostscript
8.54
ghostscriptghostscript
8.56
ghostscriptghostscript
8.57
ghostscriptghostscript
8.61
ghostscriptghostscript
8.62
ghostscriptghostscript
8.63
argyllcmsargyllcms
𝑥
≤ 1.0.3
argyllcmsargyllcms
0.1.0
argyllcmsargyllcms
0.2.0
argyllcmsargyllcms
0.2.1
argyllcmsargyllcms
0.2.2
argyllcmsargyllcms
0.3.0
argyllcmsargyllcms
0.6.0
argyllcmsargyllcms
0.7.0:beta_8
argyllcmsargyllcms
1.0.0
argyllcmsargyllcms
1.0.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
argyll
bookworm
2.3.1+repack-1.1
fixed
bullseye
2.0.1+repack-1.1
fixed
sid
3.1.0+repack-1.1
fixed
trixie
3.1.0+repack-1.1
fixed
ghostscript
bookworm
10.0.0~dfsg-11+deb12u4
fixed
bookworm (security)
10.0.0~dfsg-11+deb12u5
fixed
bullseye
9.53.3~dfsg-7+deb11u7
fixed
bullseye (security)
9.53.3~dfsg-7+deb11u8
fixed
sid
10.04.0~dfsg-1
fixed
trixie
10.04.0~dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ghostscript
dapper
dne
gutsy
ignored
hardy
Fixed 8.61.dfsg.1-1ubuntu3.2
released
intrepid
Fixed 8.63.dfsg.1-0ubuntu6.4
released
jaunty
Fixed 8.64.dfsg.1-0ubuntu8
released
karmic
Fixed 8.64.dfsg.1-0ubuntu8
released
gs-afpl
dapper
ignored
gutsy
dne
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
gs-esp
dapper
Fixed 8.15.2.dfsg.0ubuntu1-0ubuntu1.2
released
gutsy
dne
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
gs-gpl
dapper
Fixed 8.15-4ubuntu3.3
released
gutsy
dne
hardy
dne
intrepid
dne
jaunty
dne
karmic
dne
Common Weakness Enumeration
References