CVE-2009-0583Improper Restriction of Operations within the Bounds of a Memory Buffer in Ghostscript

Severity
9.3CRITICALNVD
EPSS
4.6%
top 10.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 23
Latest updateMay 2

Description

Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages3 packages

Debianartifex/ghostscript< 8.64~dfsg-1.1+3
NVDargyllcms/argyllcms1.0.3+9

🔴Vulnerability Details

3
GHSA
GHSA-hc6x-m9mp-6xc2: Multiple integer overflows in icc2022-05-02
OSV
CVE-2009-0583: Multiple integer overflows in icc2009-03-23
CVEList
CVE-2009-0583: Multiple integer overflows in icc2009-03-23

📋Vendor Advisories

5
Ubuntu
Ghostscript vulnerabilities2009-04-15
Red Hat
argyllcms: Incomplete fix for CVE-2009-05832009-04-08
Ubuntu
Ghostscript vulnerabilities2009-03-23
Red Hat
argyllcms: Multiple integer overflows in the International Color Consortium Format Library2009-03-19
Debian
CVE-2009-0583: argyll - Multiple integer overflows in icc.c in the International Color Consortium (ICC) ...2009

💬Community

8
Bugzilla
CVE-2009-0196 CVE-2009-0792 CVE-2009-0583 ghostscript various flaws [Fdevel]2009-04-15
Bugzilla
CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-05832009-03-24
Bugzilla
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [F9]2009-03-23
Bugzilla
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [Fdevel]2009-03-23
Bugzilla
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [F10]2009-03-23
CVE-2009-0583 — Ghostscript vulnerability | cvebase