CVE-2009-0584
icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.07%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 4.07% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- argyllcms/cms · ghostscript/ghostscript
- Source
- secalert@redhat.com
References
- http://bugs.gentoo.org/show_bug.cgi?id=261087
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html
- http://osvdb.org/52988
- http://secunia.com/advisories/34266
- http://secunia.com/advisories/34373Vendor Advisory
- http://secunia.com/advisories/34381Vendor Advisory
- http://secunia.com/advisories/34393Vendor Advisory
- http://secunia.com/advisories/34398Vendor Advisory
- http://secunia.com/advisories/34418
- http://secunia.com/advisories/34437Vendor Advisory
- http://secunia.com/advisories/34443
- http://secunia.com/advisories/34469
- http://secunia.com/advisories/34729
- http://secunia.com/advisories/35559
- http://secunia.com/advisories/35569
- http://securitytracker.com/id?1021868
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1
- http://support.avaya.com/elmodocs2/security/ASA-2009-098.htm
- http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0050
- http://www.auscert.org.au/render.html?it=10666US Government Resource
- http://www.debian.org/security/2009/dsa-1746
- http://www.gentoo.org/security/en/glsa/glsa-200903-37.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:095
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:096
- http://www.redhat.com/support/errata/RHSA-2009-0345.htmlVendor Advisory
- http://www.securityfocus.com/archive/1/501994/100/0/threaded
- http://www.securityfocus.com/bid/34184
- http://www.ubuntu.com/usn/USN-743-1
- http://www.vupen.com/english/advisories/2009/0776Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0777Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.