CVE-2009-0583
published 2009-03-23CVE-2009-0583: Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll…
PriorityP340critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.71%
90.8th percentile
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| argyllcms | argyllcms | <= 1.0.3 | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| debian | argyll | < argyll 1.0.3-3 (bookworm) | argyll 1.0.3-3 (bookworm) |
| debian | argyll | < argyll 1.0.3-2 (bookworm) | argyll 1.0.3-2 (bookworm) |
| debian | ghostscript | < argyll 1.0.3-3 (bookworm) | argyll 1.0.3-3 (bookworm) |
| debian | ghostscript | < argyll 1.0.3-2 (bookworm) | argyll 1.0.3-2 (bookworm) |
| ghostscript | ghostscript | <= 8.64 | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c674-58j3-3v3w: Multiple integer overflows in icc
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2009-0792 [CRITICAL] GHSA-c674-58j3-3v3w: Multiple integer overflows in icc
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
GHSA
GHSA-hc6x-m9mp-6xc2: Multiple integer overflows in icc
ghsa_unreviewed·2022-05-02
CVE-2009-0583 [HIGH] CWE-119 GHSA-hc6x-m9mp-6xc2: Multiple integer overflows in icc
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
OSV
CVE-2009-0792: Multiple integer overflows in icc
osv·2009-04-14·CVSS 9.3
CVE-2009-0792 [CRITICAL] CVE-2009-0792: Multiple integer overflows in icc
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
OSV
CVE-2009-0583: Multiple integer overflows in icc
osv·2009-03-23·CVSS 9.3
CVE-2009-0583 [CRITICAL] CVE-2009-0583: Multiple integer overflows in icc
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2009-04-15·CVSS 7.5
CVE-2007-6725 [HIGH] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Ghostscript vulnerabilities
It was discovered that Ghostscript contained a buffer underflow in its
CCITTFax decoding filter. If a user or automated system were tricked into
opening a crafted PDF file, an attacker could cause a denial of service or
execute arbitrary code with privileges of the user invoking the program.
(CVE-2007-6725)
It was discovered that Ghostscript contained a buffer overflow in the
BaseFont writer module. If a user or automated system were tricked into
opening a crafted Postscript file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program. (CVE-2008-6679)
It was discovered that Ghostscript contained additional integer overflows
in its ICC color management
Red Hat
argyllcms: Incomplete fix for CVE-2009-0583
vendor_redhat·2009-04-08·CVSS 9.3
CVE-2009-0792 [CRITICAL] argyllcms: Incomplete fix for CVE-2009-0583
argyllcms: Incomplete fix for CVE-2009-0583
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2009-03-23·CVSS 9.3
CVE-2009-0584 [CRITICAL] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Ghostscript vulnerabilities
It was discovered that Ghostscript contained multiple integer overflows in
its ICC color management library. If a user or automated system were
tricked into opening a crafted Postscript file, an attacker could cause a
denial of service or execute arbitrary code with privileges of the user
invoking the program. (CVE-2009-0583)
It was discovered that Ghostscript did not properly perform bounds checking
in its ICC color management library. If a user or automated system were
tricked into opening a crafted Postscript file, an attacker could cause a
denial of service or execute arbitrary code with privileges of the user
invoking the program. (CVE-2009-0584)
Instructions: In general, a standard system upgrade is sufficien
Red Hat
argyllcms: Multiple integer overflows in the International Color Consortium Format Library
vendor_redhat·2009-03-19·CVSS 9.3
CVE-2009-0583 [CRITICAL] CWE-190 argyllcms: Multiple integer overflows in the International Color Consortium Format Library
argyllcms: Multiple integer overflows in the International Color Consortium Format Library
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
Debian
CVE-2009-0792: argyll - Multiple integer overflows in icc.c in the International Color Consortium (ICC) ...
vendor_debian·2009·CVSS 9.3
CVE-2009-0792 [CRITICAL] CVE-2009-0792: argyll - Multiple integer overflows in icc.c in the International Color Consortium (ICC) ...
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
Scope: local
bookworm: resolved (fixed in 1.0.3-3)
bullseye: resolved (fixed in 1.0.3-3)
forky: resolved (fixed in 1.0.3-3)
sid: resolved (fixed in 1.0.3-3
Debian
CVE-2009-0583: argyll - Multiple integer overflows in icc.c in the International Color Consortium (ICC) ...
vendor_debian·2009·CVSS 9.3
CVE-2009-0583 [CRITICAL] CVE-2009-0583: argyll - Multiple integer overflows in icc.c in the International Color Consortium (ICC) ...
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
Scope: local
bookworm: resolved (fixed in 1.0.3-2)
bullseye: resolved (fixed in 1.0.3-2)
forky: resolved (fixed in 1.0.3-2)
sid: resolved (fixed in 1.0.3-2)
trixie: resolved (fixed in 1.0.3-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0196 CVE-2009-0792 CVE-2009-0583 ghostscript various flaws [Fdevel]
bugzilla·2009-04-15·CVSS 9.3
CVE-2009-0196 [CRITICAL] CVE-2009-0196 CVE-2009-0792 CVE-2009-0583 ghostscript various flaws [Fdevel]
CVE-2009-0196 CVE-2009-0792 CVE-2009-0583 ghostscript various flaws [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora 11 development cycle.
Changing version to '11'.
More information and reason for this action is here:
http://fedoraproject.org/wiki/BugZappers/HouseKeeping
Bugzilla
CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583
bugzilla·2009-03-24·CVSS 9.3
CVE-2009-0792 [CRITICAL] CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583
CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583
Multiple integer overflows and multiple insufficient upper-bounds checks on certain variable sizes were originally discovered in the Ghostscript's International Color Consortium Format Library (icclib). It was found,
the original patch, addressing this issue was incomplete.
Discussion:
Created attachment 338699
Updated ghostscript-CVE-2009-0792.patch (adds checks for all 'floor' occurences)
---
Created attachment 338705
Updated Argyllcms CVE-2009-0792 (all changes in one file) patch
---
argyllcms has now been built with this patch for rawhide, F-10 and F-9, and Bodhi updates for F-10 and F-9 have been created.
---
argyllcms-1.0.3-4.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist
Bugzilla
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [F9]
bugzilla·2009-03-23·CVSS 9.3
CVE-2009-0583 [CRITICAL] CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [F9]
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
argyllcms-1.0.3-3.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/argyllcms-1.0.3-3.fc10
---
argyllcms-1.0.3-3.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/argyllcms-1.0.3-3.fc9
---
argyllcms-1.0.3-3.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [Fdevel]
bugzilla·2009-03-23·CVSS 9.3
CVE-2009-0583 [CRITICAL] CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [Fdevel]
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
argyllcms-1.0.3-3.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/argyllcms-1.0.3-3.fc10
---
argyllcms-1.0.3-3.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/argyllcms-1.0.3-3.fc9
---
*** Bug 491743 has been marked as a duplicate of this bug. ***
Bugzilla
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [F10]
bugzilla·2009-03-23·CVSS 9.3
CVE-2009-0583 [CRITICAL] CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [F10]
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [F10]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
argyllcms-1.0.3-3.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/argyllcms-1.0.3-3.fc10
---
argyllcms-1.0.3-3.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/argyllcms-1.0.3-3.fc9
---
argyllcms-1.0.3-3.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2009-0583 CVE-2009-0584 Multiple ghostscript vulnerabilities [Fedora 10]
bugzilla·2009-03-20·CVSS 9.3
CVE-2009-0583 [CRITICAL] CVE-2009-0583 CVE-2009-0584 Multiple ghostscript vulnerabilities [Fedora 10]
CVE-2009-0583 CVE-2009-0584 Multiple ghostscript vulnerabilities [Fedora 10]
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
You should *not* refer to this bug publicly, as it is a private "Fedora Project Contributors" bug.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #487742: CVE-2009-0583 ghostscript: Multiple integer overflows in the International Color Consortium Format Library
bug #487744: CVE-2009-0584 ghostscript: Multiple insufficient upper-bounds checks on certain sizes in the International Color Consortium Format Library
When creating an update for the version this this bug is
Bugzilla
CVE-2009-0583 CVE-2009-0584 Multiple ghostscript vulnerabilities [Fedora 9]
bugzilla·2009-03-20·CVSS 9.3
CVE-2009-0583 [CRITICAL] CVE-2009-0583 CVE-2009-0584 Multiple ghostscript vulnerabilities [Fedora 9]
CVE-2009-0583 CVE-2009-0584 Multiple ghostscript vulnerabilities [Fedora 9]
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
You should *not* refer to this bug publicly, as it is a private "Fedora Project Contributors" bug.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #487742: CVE-2009-0583 ghostscript: Multiple integer overflows in the International Color Consortium Format Library
bug #487744: CVE-2009-0584 ghostscript: Multiple insufficient upper-bounds checks on certain sizes in the International Color Consortium Format Library
When creating an update for the version this this bug is r
Bugzilla
CVE-2009-0583 ghostscript, argyllcms: Multiple integer overflows in the International Color Consortium Format Library
bugzilla·2009-02-27·CVSS 4.3
CVE-2009-0583 [MEDIUM] CVE-2009-0583 ghostscript, argyllcms: Multiple integer overflows in the International Color Consortium Format Library
CVE-2009-0583 ghostscript, argyllcms: Multiple integer overflows in the International Color Consortium Format Library
Multiple integer overflows were found in the Ghostsript's International Color Consortium Format Library (icclib). An attacker could use this flaw to
potentially execute arbitrary code by requesting to translate a specially-
crafted image file created on one device into another's device native color
space via a device file.
Discussion:
Lifting embargo
---
ghostscript-8.63-2.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
---
ghostscript-8.63-5.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
---
Updates for argyll
http://bugs.gentoo.org/show_bug.cgi?id=261087http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.htmlhttp://secunia.com/advisories/34266http://secunia.com/advisories/34373http://secunia.com/advisories/34381http://secunia.com/advisories/34393http://secunia.com/advisories/34398http://secunia.com/advisories/34418http://secunia.com/advisories/34437http://secunia.com/advisories/34443http://secunia.com/advisories/34469http://secunia.com/advisories/34729http://secunia.com/advisories/35559http://secunia.com/advisories/35569http://securitytracker.com/id?1021868http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1http://support.avaya.com/elmodocs2/security/ASA-2009-098.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2009-0050http://www.auscert.org.au/render.html?it=10666http://www.debian.org/security/2009/dsa-1746http://www.gentoo.org/security/en/glsa/glsa-200903-37.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:095http://www.mandriva.com/security/advisories?name=MDVSA-2009:096http://www.redhat.com/support/errata/RHSA-2009-0345.htmlhttp://www.securityfocus.com/archive/1/501994/100/0/threadedhttp://www.securityfocus.com/bid/34184http://www.ubuntu.com/usn/USN-743-1http://www.vupen.com/english/advisories/2009/0776http://www.vupen.com/english/advisories/2009/0777http://www.vupen.com/english/advisories/2009/0816http://www.vupen.com/english/advisories/2009/1708https://bugzilla.redhat.com/show_bug.cgi?id=487742https://exchange.xforce.ibmcloud.com/vulnerabilities/49329https://issues.rpath.com/browse/RPL-2991https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10795https://usn.ubuntu.com/757-1/https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00770.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00772.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00887.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00916.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=261087http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.htmlhttp://secunia.com/advisories/34266http://secunia.com/advisories/34373http://secunia.com/advisories/34381http://secunia.com/advisories/34393http://secunia.com/advisories/34398http://secunia.com/advisories/34418http://secunia.com/advisories/34437http://secunia.com/advisories/34443http://secunia.com/advisories/34469http://secunia.com/advisories/34729http://secunia.com/advisories/35559http://secunia.com/advisories/35569http://securitytracker.com/id?1021868http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1http://support.avaya.com/elmodocs2/security/ASA-2009-098.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2009-0050http://www.auscert.org.au/render.html?it=10666http://www.debian.org/security/2009/dsa-1746http://www.gentoo.org/security/en/glsa/glsa-200903-37.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:095http://www.mandriva.com/security/advisories?name=MDVSA-2009:096http://www.redhat.com/support/errata/RHSA-2009-0345.htmlhttp://www.securityfocus.com/archive/1/501994/100/0/threadedhttp://www.securityfocus.com/bid/34184http://www.ubuntu.com/usn/USN-743-1http://www.vupen.com/english/advisories/2009/0776http://www.vupen.com/english/advisories/2009/0777http://www.vupen.com/english/advisories/2009/0816http://www.vupen.com/english/advisories/2009/1708https://bugzilla.redhat.com/show_bug.cgi?id=487742https://exchange.xforce.ibmcloud.com/vulnerabilities/49329https://issues.rpath.com/browse/RPL-2991https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10795https://usn.ubuntu.com/757-1/https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00770.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00772.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00887.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00916.html
2009-03-23
Published