CVE-2012-4405
published 2012-09-18CVE-2012-4405: Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and…
PriorityP337medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
7.49%
93.8th percentile
Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | >= 0 < 9.05~dfsg-6.1 | 9.05~dfsg-6.1 |
| artifex | ghostscript | >= 0 < 9.05~dfsg-6.1 | 9.05~dfsg-6.1 |
| artifex | ghostscript | >= 0 < 9.05~dfsg-6.1 | 9.05~dfsg-6.1 |
| artifex | ghostscript | >= 0 < 9.05~dfsg-6.1 | 9.05~dfsg-6.1 |
| debian | argyll | < argyll 1.4.0-7 (bookworm) | argyll 1.4.0-7 (bookworm) |
| debian | ghostscript | < argyll 1.4.0-7 (bookworm) | argyll 1.4.0-7 (bookworm) |
| ghostscript | ghostscript | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ghostscript vulnerability
vendor_ubuntu·2012-09-24
CVE-2012-4405 Ghostscript vulnerability
Title: Ghostscript vulnerability
Summary: Ghostscript could be made to crash or run programs as your login if it
opened a specially crafted file.
Marc Schönefeld discovered that Ghostscript did not correctly handle
certain image files. If a user or automated system were tricked into
opening a specially crafted file, an attacker could cause a denial of
service and possibly execute arbitrary code with user privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
argyllcms: Array index error leading to heap-based bufer OOB write
vendor_redhat·2012-09-11·CVSS 6.8
CVE-2012-4405 [MEDIUM] CWE-787 argyllcms: Array index error leading to heap-based bufer OOB write
argyllcms: Array index error leading to heap-based bufer OOB write
Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error.
Debian
CVE-2012-4405: argyll - Multiple integer underflows in the icmLut_allocate function in International Col...
vendor_debian·2012·CVSS 6.8
CVE-2012-4405 [MEDIUM] CVE-2012-4405: argyll - Multiple integer underflows in the icmLut_allocate function in International Col...
Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error.
Scope: local
bookworm: resolved (fixed in 1.4.0-7)
bullseye: resolved (fixed in 1.4.0-7)
forky: resolved (fixed in 1.4.0-7)
sid: resolved (fixed in 1.4.0-7)
trixie: resolved (fixed in 1.4.0-7)
GHSA
GHSA-6vmw-rrmp-q45c: Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9
ghsa_unreviewed·2022-05-17
CVE-2012-4405 [MEDIUM] GHSA-6vmw-rrmp-q45c: Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9
Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error.
OSV
CVE-2012-4405: Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9
osv·2012-09-18·CVSS 6.8
CVE-2012-4405 [MEDIUM] CVE-2012-4405: Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9
Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-4405 ghostscript, argyllcms: Array index error leading to heap-based bufer OOB write [fedora-all]
bugzilla·2012-09-11·CVSS 6.8
CVE-2012-4405 [MEDIUM] CVE-2012-4405 ghostscript, argyllcms: Array index error leading to heap-based bufer OOB write [fedora-all]
CVE-2012-4405 ghostscript, argyllcms: Array index error leading to heap-based bufer OOB write [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.
Bugzilla
CVE-2012-4405 ghostscript, argyllcms: Array index error leading to heap-based bufer OOB write [fedora-all]
bugzilla·2012-09-11·CVSS 6.8
CVE-2012-4405 [MEDIUM] CVE-2012-4405 ghostscript, argyllcms: Array index error leading to heap-based bufer OOB write [fedora-all]
CVE-2012-4405 ghostscript, argyllcms: Array index error leading to heap-based bufer OOB write [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.
Bugzilla
CVE-2012-4405 ghostscript, argyllcms: Array index error leading to heap-based bufer OOB write
bugzilla·2012-09-04·CVSS 6.8
CVE-2012-4405 [MEDIUM] CVE-2012-4405 ghostscript, argyllcms: Array index error leading to heap-based bufer OOB write
CVE-2012-4405 ghostscript, argyllcms: Array index error leading to heap-based bufer OOB write
An array index error leading to heap-based buffer out-of-buffer bounds write flaw was found in the way International Color Consortium (ICC) Format library (aka icclib) as used in Ghostscript and Argyll Color Management System computed dimensional increment through the clut based on the count of input channels. Using specially-crafted ICC profiles, an attacker could create a malicious PostScript or PDF file with embedded images which would cause Ghostscript to crash or, potentially, execute arbitrary code when opened by the victim. Similarly when such specially-crafted ICC profile was inspected by some of the Argyll Color Management System tools it could lead to particular executable crash or, arb
http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1256.htmlhttp://secunia.com/advisories/50719http://security.gentoo.org/glsa/glsa-201412-17.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:151http://www.mandriva.com/security/advisories?name=MDVSA-2013:089http://www.mandriva.com/security/advisories?name=MDVSA-2013:090http://www.openwall.com/lists/oss-security/2012/09/11/2http://www.securityfocus.com/bid/55494http://www.securitytracker.com/id?1027517http://www.ubuntu.com/usn/USN-1581-1https://exchange.xforce.ibmcloud.com/vulnerabilities/78411https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0301http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-updates/2012-10/msg00015.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1256.htmlhttp://secunia.com/advisories/50719http://security.gentoo.org/glsa/glsa-201412-17.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:151http://www.mandriva.com/security/advisories?name=MDVSA-2013:089http://www.mandriva.com/security/advisories?name=MDVSA-2013:090http://www.openwall.com/lists/oss-security/2012/09/11/2http://www.securityfocus.com/bid/55494http://www.securitytracker.com/id?1027517http://www.ubuntu.com/usn/USN-1581-1https://exchange.xforce.ibmcloud.com/vulnerabilities/78411https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0301
2012-09-18
Published