CVE-2009-0584
published 2009-03-23CVE-2009-0584: icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS)…
PriorityP339critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
4.07%
89.5th percentile
icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| argyllcms | cms | <= 1.0.3 | — |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| debian | argyll | < argyll 1.0.3-2 (bookworm) | argyll 1.0.3-2 (bookworm) |
| debian | ghostscript | < argyll 1.0.3-2 (bookworm) | argyll 1.0.3-2 (bookworm) |
| ghostscript | ghostscript | <= 8.64 | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3cwm-mjh6-3hwq: icc
ghsa_unreviewed·2022-05-02
CVE-2009-0584 [HIGH] GHSA-3cwm-mjh6-3hwq: icc
icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
OSV
CVE-2009-0584: icc
osv·2009-03-23·CVSS 9.3
CVE-2009-0584 [CRITICAL] CVE-2009-0584: icc
icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2009-04-15·CVSS 7.5
CVE-2007-6725 [HIGH] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Ghostscript vulnerabilities
It was discovered that Ghostscript contained a buffer underflow in its
CCITTFax decoding filter. If a user or automated system were tricked into
opening a crafted PDF file, an attacker could cause a denial of service or
execute arbitrary code with privileges of the user invoking the program.
(CVE-2007-6725)
It was discovered that Ghostscript contained a buffer overflow in the
BaseFont writer module. If a user or automated system were tricked into
opening a crafted Postscript file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program. (CVE-2008-6679)
It was discovered that Ghostscript contained additional integer overflows
in its ICC color management
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2009-03-23·CVSS 9.3
CVE-2009-0584 [CRITICAL] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Ghostscript vulnerabilities
It was discovered that Ghostscript contained multiple integer overflows in
its ICC color management library. If a user or automated system were
tricked into opening a crafted Postscript file, an attacker could cause a
denial of service or execute arbitrary code with privileges of the user
invoking the program. (CVE-2009-0583)
It was discovered that Ghostscript did not properly perform bounds checking
in its ICC color management library. If a user or automated system were
tricked into opening a crafted Postscript file, an attacker could cause a
denial of service or execute arbitrary code with privileges of the user
invoking the program. (CVE-2009-0584)
Instructions: In general, a standard system upgrade is sufficien
Red Hat
argyllcms: Multiple insufficient upper-bounds checks on certain sizes in the International Color Consortium Format Library
vendor_redhat·2009-03-19·CVSS 9.3
CVE-2009-0584 [CRITICAL] argyllcms: Multiple insufficient upper-bounds checks on certain sizes in the International Color Consortium Format Library
argyllcms: Multiple insufficient upper-bounds checks on certain sizes in the International Color Consortium Format Library
icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
Debian
CVE-2009-0584: argyll - icc.c in the International Color Consortium (ICC) Format library (aka icclib), a...
vendor_debian·2009·CVSS 9.3
CVE-2009-0584 [CRITICAL] CVE-2009-0584: argyll - icc.c in the International Color Consortium (ICC) Format library (aka icclib), a...
icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
Scope: local
bookworm: resolved (fixed in 1.0.3-2)
bullseye: resolved (fixed in 1.0.3-2)
forky: resolved (fixed in 1.0.3-2)
sid: resolved (fixed in 1.0.3-2)
trixie: resolved (fixed in 1.0.3-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [F9]
bugzilla·2009-03-23·CVSS 9.3
CVE-2009-0583 [CRITICAL] CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [F9]
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
argyllcms-1.0.3-3.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/argyllcms-1.0.3-3.fc10
---
argyllcms-1.0.3-3.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/argyllcms-1.0.3-3.fc9
---
argyllcms-1.0.3-3.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [Fdevel]
bugzilla·2009-03-23·CVSS 9.3
CVE-2009-0583 [CRITICAL] CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [Fdevel]
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
argyllcms-1.0.3-3.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/argyllcms-1.0.3-3.fc10
---
argyllcms-1.0.3-3.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/argyllcms-1.0.3-3.fc9
---
*** Bug 491743 has been marked as a duplicate of this bug. ***
Bugzilla
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [F10]
bugzilla·2009-03-23·CVSS 9.3
CVE-2009-0583 [CRITICAL] CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [F10]
CVE-2009-0583 CVE-2009-0584 Multiple argyllcms vulnerabilities [F10]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
argyllcms-1.0.3-3.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/argyllcms-1.0.3-3.fc10
---
argyllcms-1.0.3-3.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/argyllcms-1.0.3-3.fc9
---
argyllcms-1.0.3-3.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2009-0583 CVE-2009-0584 Multiple ghostscript vulnerabilities [Fedora 10]
bugzilla·2009-03-20·CVSS 9.3
CVE-2009-0583 [CRITICAL] CVE-2009-0583 CVE-2009-0584 Multiple ghostscript vulnerabilities [Fedora 10]
CVE-2009-0583 CVE-2009-0584 Multiple ghostscript vulnerabilities [Fedora 10]
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
You should *not* refer to this bug publicly, as it is a private "Fedora Project Contributors" bug.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #487742: CVE-2009-0583 ghostscript: Multiple integer overflows in the International Color Consortium Format Library
bug #487744: CVE-2009-0584 ghostscript: Multiple insufficient upper-bounds checks on certain sizes in the International Color Consortium Format Library
When creating an update for the version this this bug is
Bugzilla
CVE-2009-0583 CVE-2009-0584 Multiple ghostscript vulnerabilities [Fedora 9]
bugzilla·2009-03-20·CVSS 9.3
CVE-2009-0583 [CRITICAL] CVE-2009-0583 CVE-2009-0584 Multiple ghostscript vulnerabilities [Fedora 9]
CVE-2009-0583 CVE-2009-0584 Multiple ghostscript vulnerabilities [Fedora 9]
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
You should *not* refer to this bug publicly, as it is a private "Fedora Project Contributors" bug.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #487742: CVE-2009-0583 ghostscript: Multiple integer overflows in the International Color Consortium Format Library
bug #487744: CVE-2009-0584 ghostscript: Multiple insufficient upper-bounds checks on certain sizes in the International Color Consortium Format Library
When creating an update for the version this this bug is r
Bugzilla
CVE-2009-0584 ghostscript, argyllcms: Multiple insufficient upper-bounds checks on certain sizes in the International Color Consortium Format Library
bugzilla·2009-02-27·CVSS 7.2
CVE-2009-0584 [HIGH] CVE-2009-0584 ghostscript, argyllcms: Multiple insufficient upper-bounds checks on certain sizes in the International Color Consortium Format Library
CVE-2009-0584 ghostscript, argyllcms: Multiple insufficient upper-bounds checks on certain sizes in the International Color Consortium Format Library
Multiple insufficient upper-bounds checks on certain sizes were found in the
Ghostscript's International Color Consortium Format Library (icclib). An
attacker could use this flaw to potentially execute arbitrary code by
providing a specially-crafted image file for processing via the Ghotstscript's
device file.
Discussion:
Lifting embargo
---
ghostscript-8.63-2.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
---
ghostscript-8.63-5.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
---
http://bugs.gentoo.org/show_bug.cgi?id=261087http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.htmlhttp://osvdb.org/52988http://secunia.com/advisories/34266http://secunia.com/advisories/34373http://secunia.com/advisories/34381http://secunia.com/advisories/34393http://secunia.com/advisories/34398http://secunia.com/advisories/34418http://secunia.com/advisories/34437http://secunia.com/advisories/34443http://secunia.com/advisories/34469http://secunia.com/advisories/34729http://secunia.com/advisories/35559http://secunia.com/advisories/35569http://securitytracker.com/id?1021868http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1http://support.avaya.com/elmodocs2/security/ASA-2009-098.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2009-0050http://www.auscert.org.au/render.html?it=10666http://www.debian.org/security/2009/dsa-1746http://www.gentoo.org/security/en/glsa/glsa-200903-37.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:095http://www.mandriva.com/security/advisories?name=MDVSA-2009:096http://www.redhat.com/support/errata/RHSA-2009-0345.htmlhttp://www.securityfocus.com/archive/1/501994/100/0/threadedhttp://www.securityfocus.com/bid/34184http://www.ubuntu.com/usn/USN-743-1http://www.vupen.com/english/advisories/2009/0776http://www.vupen.com/english/advisories/2009/0777http://www.vupen.com/english/advisories/2009/0816http://www.vupen.com/english/advisories/2009/1708https://bugzilla.redhat.com/show_bug.cgi?id=487744https://exchange.xforce.ibmcloud.com/vulnerabilities/49327https://issues.rpath.com/browse/RPL-2991https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10544https://usn.ubuntu.com/757-1/https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00770.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00772.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00887.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00916.htmlhttp://bugs.gentoo.org/show_bug.cgi?id=261087http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.htmlhttp://osvdb.org/52988http://secunia.com/advisories/34266http://secunia.com/advisories/34373http://secunia.com/advisories/34381http://secunia.com/advisories/34393http://secunia.com/advisories/34398http://secunia.com/advisories/34418http://secunia.com/advisories/34437http://secunia.com/advisories/34443http://secunia.com/advisories/34469http://secunia.com/advisories/34729http://secunia.com/advisories/35559http://secunia.com/advisories/35569http://securitytracker.com/id?1021868http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1http://support.avaya.com/elmodocs2/security/ASA-2009-098.htmhttp://wiki.rpath.com/wiki/Advisories:rPSA-2009-0050http://www.auscert.org.au/render.html?it=10666http://www.debian.org/security/2009/dsa-1746http://www.gentoo.org/security/en/glsa/glsa-200903-37.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:095http://www.mandriva.com/security/advisories?name=MDVSA-2009:096http://www.redhat.com/support/errata/RHSA-2009-0345.htmlhttp://www.securityfocus.com/archive/1/501994/100/0/threadedhttp://www.securityfocus.com/bid/34184http://www.ubuntu.com/usn/USN-743-1http://www.vupen.com/english/advisories/2009/0776http://www.vupen.com/english/advisories/2009/0777http://www.vupen.com/english/advisories/2009/0816http://www.vupen.com/english/advisories/2009/1708https://bugzilla.redhat.com/show_bug.cgi?id=487744https://exchange.xforce.ibmcloud.com/vulnerabilities/49327https://issues.rpath.com/browse/RPL-2991https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10544https://usn.ubuntu.com/757-1/https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00770.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00772.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00887.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-March/msg00916.html
2009-03-23
Published