PT-2009-3227 · Artifex+2 · Ghostscript+2

Jan Lieskovsky

·

Published

2009-03-19

·

Updated

2023-02-13

·

CVE-2009-0583

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ghostscript versions 8.64 and earlier Argyll Color Management System (CMS) versions 1.0.3 and earlier
Description The issue is related to multiple integer overflows in the ICC Format library, which can be exploited by context-dependent attackers to cause a denial of service or possibly execute arbitrary code. This can be achieved by using a device file for a translation request that operates on a crafted image file, targeting a certain "native color space" related to an ICC profile in a PostScript or PDF file with embedded images.
Recommendations For Ghostscript versions 8.64 and earlier, update to a version later than 8.64 to resolve the issue. For Argyll Color Management System (CMS) versions 1.0.3 and earlier, update to a version later than 1.0.3 to resolve the issue. As a temporary workaround, consider restricting the use of device files for translation requests that operate on crafted image files to minimize the risk of exploitation.

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2009-0583
DSA-1746-1
DTSA-198-1
RHSA-2009:0345
RHSA-2009_0345

Affected Products

Argyll Color Management System
Ghostscript
Red Hat