Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-4405

Опубликовано: 18 сент. 2012
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 6.8

Описание

Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error.

РелизСтатусПримечание
devel

not-affected

1.4.0-7ubuntu1
esm-apps/xenial

not-affected

1.4.0-7ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [1.4.0-7ubuntu1]]
hardy

DNE

lucid

ignored

end of life
natty

ignored

end of life
oneiric

ignored

end of life
precise

ignored

end of life
precise/esm

DNE

precise was needs-triage
quantal

not-affected

1.4.0-7ubuntu1

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [code not present]]
esm-infra/xenial

not-affected

code not present
hardy

released

8.61.dfsg.1-1ubuntu3.5
lucid

released

8.71.dfsg.1-0ubuntu5.5
natty

not-affected

code not present
oneiric

not-affected

precise

not-affected

code not present
precise/esm

DNE

precise was not-affected [code not present]
quantal

not-affected

code not present

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

hardy

DNE

lucid

DNE

natty

DNE

oneiric

DNE

precise

DNE

precise/esm

DNE

quantal

DNE

raring

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

hardy

DNE

lucid

DNE

natty

DNE

oneiric

DNE

precise

DNE

precise/esm

DNE

quantal

DNE

raring

DNE

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

hardy

DNE

lucid

DNE

natty

DNE

oneiric

DNE

precise

DNE

precise/esm

DNE

quantal

DNE

raring

DNE

Показывать по

EPSS

Процентиль: 97%
0.3537
Средний

6.8 Medium

CVSS2

Связанные уязвимости

redhat
почти 13 лет назад

Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error.

nvd
почти 13 лет назад

Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error.

debian
почти 13 лет назад

Multiple integer underflows in the icmLut_allocate function in Interna ...

github
больше 3 лет назад

Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error.

oracle-oval
почти 13 лет назад

ELSA-2012-1256: ghostscript security update (MODERATE)

EPSS

Процентиль: 97%
0.3537
Средний

6.8 Medium

CVSS2

Уязвимость CVE-2012-4405