PT-2009-3228 · Artifex+2 · Ghostscript+2

Jan Lieskovsky

·

Published

2009-03-19

·

Updated

2018-10-10

·

CVE-2009-0584

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ghostscript versions 8.64 and earlier Argyll Color Management System (CMS) versions 1.0.3 and earlier
Description The issue allows context-dependent attackers to cause a denial of service, resulting in an application crash, or possibly execute arbitrary code. This can be achieved by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a PostScript or a PDF file with embedded images.
Recommendations For Ghostscript versions 8.64 and earlier, consider updating to a newer version to mitigate the risk. For Argyll Color Management System (CMS) versions 1.0.3 and earlier, consider updating to a newer version to mitigate the risk. As a temporary workaround, consider restricting the use of ICC profiles in PostScript or PDF files with embedded images until a patch is available.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0584
DSA-1746-1
DTSA-198-1
RHSA-2009:0345
RHSA-2009_0345

Affected Products

Argyll Color Management System
Ghostscript
Red Hat