Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2009-0345

Опубликовано: 19 мар. 2009
Источник: oracle-oval
Платформа: Oracle Linux 5

Описание

ELSA-2009-0345: ghostscript security update (MODERATE)

[8.15.2-9.4:.4]

  • Avoid dividing by zero while checking for integer overflows.

[8.15.2-9.4:.1]

  • Applied patch to fix CVE-2009-0583 (bug #487742) and CVE-2009-0584 (bug #487744).

Обновленные пакеты

Oracle Linux 5

Oracle Linux x86_64

ghostscript

8.15.2-9.4.el5_3.4

ghostscript-devel

8.15.2-9.4.el5_3.4

ghostscript-gtk

8.15.2-9.4.el5_3.4

Oracle Linux i386

ghostscript

8.15.2-9.4.el5_3.4

ghostscript-devel

8.15.2-9.4.el5_3.4

ghostscript-gtk

8.15.2-9.4.el5_3.4

Связанные CVE

Связанные уязвимости

ubuntu
около 16 лет назад

icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.

redhat
больше 16 лет назад

icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.

nvd
около 16 лет назад

icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.

debian
около 16 лет назад

icc.c in the International Color Consortium (ICC) Format library (aka ...

ubuntu
около 16 лет назад

Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.