Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-0583

Опубликовано: 23 мар. 2009
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 9.3

Описание

Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.

РелизСтатусПримечание
dapper

DNE

devel

released

8.64.dfsg.1-0ubuntu6
gutsy

released

8.61.dfsg.1~svn8187-0ubuntu3.5
hardy

released

8.61.dfsg.1-1ubuntu3.1
intrepid

released

8.63.dfsg.1-0ubuntu6.3
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

released

8.15-4ubuntu3.2
devel

DNE

gutsy

DNE

hardy

DNE

intrepid

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 88%
0.04082
Низкий

9.3 Critical

CVSS2

Связанные уязвимости

redhat
больше 16 лет назад

Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.

nvd
около 16 лет назад

Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.

debian
около 16 лет назад

Multiple integer overflows in icc.c in the International Color Consort ...

github
около 3 лет назад

Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.

oracle-oval
больше 16 лет назад

ELSA-2009-0345: ghostscript security update (MODERATE)

EPSS

Процентиль: 88%
0.04082
Низкий

9.3 Critical

CVSS2

Уязвимость CVE-2009-0583