CVE-2009-0792
published 2009-04-14CVE-2009-0792: Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll…
PriorityP339critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.99%
89.4th percentile
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| argyllcms | argyllcms | <= 1.0.3 | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| argyllcms | argyllcms | — | — |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-1.1 | 8.64~dfsg-1.1 |
| debian | argyll | < argyll 1.0.3-3 (bookworm) | argyll 1.0.3-3 (bookworm) |
| debian | ghostscript | < argyll 1.0.3-3 (bookworm) | argyll 1.0.3-3 (bookworm) |
| ghostscript | ghostscript | <= 8.64 | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
| ghostscript | ghostscript | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3MEDIUM
vendor_redhat9.3CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c674-58j3-3v3w: Multiple integer overflows in icc
ghsa_unreviewed·2022-05-02·CVSS 9.3
CVE-2009-0792 [CRITICAL] GHSA-c674-58j3-3v3w: Multiple integer overflows in icc
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
OSV
CVE-2009-0792: Multiple integer overflows in icc
osv·2009-04-14·CVSS 9.3
CVE-2009-0792 [CRITICAL] CVE-2009-0792: Multiple integer overflows in icc
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2009-04-15·CVSS 7.5
CVE-2007-6725 [HIGH] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Ghostscript vulnerabilities
It was discovered that Ghostscript contained a buffer underflow in its
CCITTFax decoding filter. If a user or automated system were tricked into
opening a crafted PDF file, an attacker could cause a denial of service or
execute arbitrary code with privileges of the user invoking the program.
(CVE-2007-6725)
It was discovered that Ghostscript contained a buffer overflow in the
BaseFont writer module. If a user or automated system were tricked into
opening a crafted Postscript file, an attacker could cause a denial of
service or execute arbitrary code with privileges of the user invoking the
program. (CVE-2008-6679)
It was discovered that Ghostscript contained additional integer overflows
in its ICC color management
Red Hat
argyllcms: Incomplete fix for CVE-2009-0583
vendor_redhat·2009-04-08·CVSS 9.3
CVE-2009-0792 [CRITICAL] argyllcms: Incomplete fix for CVE-2009-0583
argyllcms: Incomplete fix for CVE-2009-0583
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
Debian
CVE-2009-0792: argyll - Multiple integer overflows in icc.c in the International Color Consortium (ICC) ...
vendor_debian·2009·CVSS 9.3
CVE-2009-0792 [CRITICAL] CVE-2009-0792: argyll - Multiple integer overflows in icc.c in the International Color Consortium (ICC) ...
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
Scope: local
bookworm: resolved (fixed in 1.0.3-3)
bullseye: resolved (fixed in 1.0.3-3)
forky: resolved (fixed in 1.0.3-3)
sid: resolved (fixed in 1.0.3-3
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F10]
bugzilla·2009-04-15·CVSS 5.0
CVE-2008-6679 [MEDIUM] CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F10]
CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F10]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
*** Bug 480775 has been marked as a duplicate of this bug. ***
---
ghostscript-8.63-6.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/ghostscript-8.63-6.fc10
---
ghostscript-8.63-6.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2009-0196 CVE-2009-0792 CVE-2009-0583 ghostscript various flaws [Fdevel]
bugzilla·2009-04-15·CVSS 9.3
CVE-2009-0196 [CRITICAL] CVE-2009-0196 CVE-2009-0792 CVE-2009-0583 ghostscript various flaws [Fdevel]
CVE-2009-0196 CVE-2009-0792 CVE-2009-0583 ghostscript various flaws [Fdevel]
Fdevel tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
This bug appears to have been reported against 'rawhide' during the Fedora 11 development cycle.
Changing version to '11'.
More information and reason for this action is here:
http://fedoraproject.org/wiki/BugZappers/HouseKeeping
Bugzilla
CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F9]
bugzilla·2009-04-15·CVSS 5.0
CVE-2008-6679 [MEDIUM] CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F9]
CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 ghostscript various flaws [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
ghostscript-8.63-3.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/ghostscript-8.63-3.fc9
---
ghostscript-8.63-3.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583
bugzilla·2009-03-24·CVSS 9.3
CVE-2009-0792 [CRITICAL] CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583
CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583
Multiple integer overflows and multiple insufficient upper-bounds checks on certain variable sizes were originally discovered in the Ghostscript's International Color Consortium Format Library (icclib). It was found,
the original patch, addressing this issue was incomplete.
Discussion:
Created attachment 338699
Updated ghostscript-CVE-2009-0792.patch (adds checks for all 'floor' occurences)
---
Created attachment 338705
Updated Argyllcms CVE-2009-0792 (all changes in one file) patch
---
argyllcms has now been built with this patch for rawhide, F-10 and F-9, and Bodhi updates for F-10 and F-9 have been created.
---
argyllcms-1.0.3-4.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://secunia.com/advisories/34373http://secunia.com/advisories/34667http://secunia.com/advisories/34711http://secunia.com/advisories/34726http://secunia.com/advisories/34729http://secunia.com/advisories/34732http://secunia.com/advisories/35416http://secunia.com/advisories/35559http://secunia.com/advisories/35569http://security.gentoo.org/glsa/glsa-201412-17.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1http://support.avaya.com/elmodocs2/security/ASA-2009-155.htmhttp://wiki.rpath.com/Advisories:rPSA-2009-0060http://www.mandriva.com/security/advisories?name=MDVSA-2009:095http://www.mandriva.com/security/advisories?name=MDVSA-2009:096http://www.redhat.com/support/errata/RHSA-2009-0420.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0421.htmlhttp://www.securityfocus.com/archive/1/502757/100/0/threadedhttp://www.vupen.com/english/advisories/2009/1708https://bugzilla.redhat.com/show_bug.cgi?id=491853https://exchange.xforce.ibmcloud.com/vulnerabilities/50381https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11207https://usn.ubuntu.com/757-1/https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00211.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00217.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00460.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00461.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.htmlhttp://secunia.com/advisories/34373http://secunia.com/advisories/34667http://secunia.com/advisories/34711http://secunia.com/advisories/34726http://secunia.com/advisories/34729http://secunia.com/advisories/34732http://secunia.com/advisories/35416http://secunia.com/advisories/35559http://secunia.com/advisories/35569http://security.gentoo.org/glsa/glsa-201412-17.xmlhttp://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1http://support.avaya.com/elmodocs2/security/ASA-2009-155.htmhttp://wiki.rpath.com/Advisories:rPSA-2009-0060http://www.mandriva.com/security/advisories?name=MDVSA-2009:095http://www.mandriva.com/security/advisories?name=MDVSA-2009:096http://www.redhat.com/support/errata/RHSA-2009-0420.htmlhttp://www.redhat.com/support/errata/RHSA-2009-0421.htmlhttp://www.securityfocus.com/archive/1/502757/100/0/threadedhttp://www.vupen.com/english/advisories/2009/1708https://bugzilla.redhat.com/show_bug.cgi?id=491853https://exchange.xforce.ibmcloud.com/vulnerabilities/50381https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11207https://usn.ubuntu.com/757-1/https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00211.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00217.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00460.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-April/msg00461.html
2009-04-14
Published