CVE-2009-0583
argyllcms: Multiple integer overflows in the International Color Consortium Format Library
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
Múltiples desbordamientos de enteros en icc.c en la libreria de formatos (alias icclib) del International Color Consortium (ICC), tal como se utiliza en Ghostscript 8.64 y anteriores y Argyll Color Management System (CMS) 1.0.3 y anteriores, permiten causar una denegación de servicio (con desbordamiento de búfer basado en pila y caída de la aplicación) a atacantes dependientes de contexto y posiblemente ejecutar código arbitrario por medio de un fichero de dispositivo para una solicitud de traducción que opera en un archivo de imagen creado y se dirige a un determinado "espacio de color nativo", en relación con un perfil ICC en un (1) PostScript o (2) archivo PDF con imágenes incrustadas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-02-13 CVE Reserved
- 2009-03-23 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-06 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-190: Integer Overflow or Wraparound
CAPEC
References (41)
URL | Tag | Source |
---|---|---|
http://bugs.gentoo.org/show_bug.cgi?id=261087 | X_refsource_confirm | |
http://secunia.com/advisories/34729 | Third Party Advisory | |
http://secunia.com/advisories/35559 | Third Party Advisory | |
http://secunia.com/advisories/35569 | Third Party Advisory | |
http://securitytracker.com/id?1021868 | Vdb Entry | |
http://support.avaya.com/elmodocs2/security/ASA-2009-098.htm | X_refsource_confirm | |
http://www.auscert.org.au/render.html?it=10666 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/501994/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/34184 | Vdb Entry | |
http://www.vupen.com/english/advisories/2009/1708 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/49329 | Vdb Entry | |
https://issues.rpath.com/browse/RPL-2991 | X_refsource_confirm | |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10795 | Signature |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ghostscript Search vendor "Ghostscript" | Ghostscript Search vendor "Ghostscript" for product "Ghostscript" | <= 8.64 Search vendor "Ghostscript" for product "Ghostscript" and version " <= 8.64" | - |
Affected
| ||||||
Ghostscript Search vendor "Ghostscript" | Ghostscript Search vendor "Ghostscript" for product "Ghostscript" | 5.50 Search vendor "Ghostscript" for product "Ghostscript" and version "5.50" | - |
Affected
| ||||||
Ghostscript Search vendor "Ghostscript" | Ghostscript Search vendor "Ghostscript" for product "Ghostscript" | 7.05 Search vendor "Ghostscript" for product "Ghostscript" and version "7.05" | - |
Affected
| ||||||
Ghostscript Search vendor "Ghostscript" | Ghostscript Search vendor "Ghostscript" for product "Ghostscript" | 7.07 Search vendor "Ghostscript" for product "Ghostscript" and version "7.07" | - |
Affected
| ||||||
Ghostscript Search vendor "Ghostscript" | Ghostscript Search vendor "Ghostscript" for product "Ghostscript" | 8.0.1 Search vendor "Ghostscript" for product "Ghostscript" and version "8.0.1" | - |
Affected
| ||||||
Ghostscript Search vendor "Ghostscript" | Ghostscript Search vendor "Ghostscript" for product "Ghostscript" | 8.15 Search vendor "Ghostscript" for product "Ghostscript" and version "8.15" | - |
Affected
| ||||||
Ghostscript Search vendor "Ghostscript" | Ghostscript Search vendor "Ghostscript" for product "Ghostscript" | 8.15.2 Search vendor "Ghostscript" for product "Ghostscript" and version "8.15.2" | - |
Affected
| ||||||
Ghostscript Search vendor "Ghostscript" | Ghostscript Search vendor "Ghostscript" for product "Ghostscript" | 8.54 Search vendor "Ghostscript" for product "Ghostscript" and version "8.54" | - |
Affected
| ||||||
Ghostscript Search vendor "Ghostscript" | Ghostscript Search vendor "Ghostscript" for product "Ghostscript" | 8.56 Search vendor "Ghostscript" for product "Ghostscript" and version "8.56" | - |
Affected
| ||||||
Ghostscript Search vendor "Ghostscript" | Ghostscript Search vendor "Ghostscript" for product "Ghostscript" | 8.57 Search vendor "Ghostscript" for product "Ghostscript" and version "8.57" | - |
Affected
| ||||||
Ghostscript Search vendor "Ghostscript" | Ghostscript Search vendor "Ghostscript" for product "Ghostscript" | 8.61 Search vendor "Ghostscript" for product "Ghostscript" and version "8.61" | - |
Affected
| ||||||
Ghostscript Search vendor "Ghostscript" | Ghostscript Search vendor "Ghostscript" for product "Ghostscript" | 8.62 Search vendor "Ghostscript" for product "Ghostscript" and version "8.62" | - |
Affected
| ||||||
Ghostscript Search vendor "Ghostscript" | Ghostscript Search vendor "Ghostscript" for product "Ghostscript" | 8.63 Search vendor "Ghostscript" for product "Ghostscript" and version "8.63" | - |
Affected
| ||||||
Argyllcms Search vendor "Argyllcms" | Argyllcms Search vendor "Argyllcms" for product "Argyllcms" | <= 1.0.3 Search vendor "Argyllcms" for product "Argyllcms" and version " <= 1.0.3" | - |
Affected
| ||||||
Argyllcms Search vendor "Argyllcms" | Argyllcms Search vendor "Argyllcms" for product "Argyllcms" | 0.1.0 Search vendor "Argyllcms" for product "Argyllcms" and version "0.1.0" | - |
Affected
| ||||||
Argyllcms Search vendor "Argyllcms" | Argyllcms Search vendor "Argyllcms" for product "Argyllcms" | 0.2.0 Search vendor "Argyllcms" for product "Argyllcms" and version "0.2.0" | - |
Affected
| ||||||
Argyllcms Search vendor "Argyllcms" | Argyllcms Search vendor "Argyllcms" for product "Argyllcms" | 0.2.1 Search vendor "Argyllcms" for product "Argyllcms" and version "0.2.1" | - |
Affected
| ||||||
Argyllcms Search vendor "Argyllcms" | Argyllcms Search vendor "Argyllcms" for product "Argyllcms" | 0.2.2 Search vendor "Argyllcms" for product "Argyllcms" and version "0.2.2" | - |
Affected
| ||||||
Argyllcms Search vendor "Argyllcms" | Argyllcms Search vendor "Argyllcms" for product "Argyllcms" | 0.3.0 Search vendor "Argyllcms" for product "Argyllcms" and version "0.3.0" | - |
Affected
| ||||||
Argyllcms Search vendor "Argyllcms" | Argyllcms Search vendor "Argyllcms" for product "Argyllcms" | 0.6.0 Search vendor "Argyllcms" for product "Argyllcms" and version "0.6.0" | - |
Affected
| ||||||
Argyllcms Search vendor "Argyllcms" | Argyllcms Search vendor "Argyllcms" for product "Argyllcms" | 0.7.0 Search vendor "Argyllcms" for product "Argyllcms" and version "0.7.0" | beta_8 |
Affected
| ||||||
Argyllcms Search vendor "Argyllcms" | Argyllcms Search vendor "Argyllcms" for product "Argyllcms" | 1.0.0 Search vendor "Argyllcms" for product "Argyllcms" and version "1.0.0" | - |
Affected
| ||||||
Argyllcms Search vendor "Argyllcms" | Argyllcms Search vendor "Argyllcms" for product "Argyllcms" | 1.0.2 Search vendor "Argyllcms" for product "Argyllcms" and version "1.0.2" | - |
Affected
|