LWN.net Logo

ghostscript: integer overflows

Package(s):ghostscript CVE #(s):CVE-2009-0792
Created:April 9, 2009 Updated:August 2, 2010
Description: Ghostscript has multiple integer overflows. The The National Vulnerability Database entry states: Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
Alerts:
Debian DSA-2080-1 2010-08-01
Mandriva MDVSA-2009:311 2009-12-03
Slackware SSA:2009-181-01 2009-06-30
SuSE SUSE-SR:2009:011 2009-06-09
Mandriva MDVSA-2009:096-1 2009-04-24
SuSE SUSE-SR:2009:009 2009-04-21
Fedora FEDORA-2009-3740 2009-04-17
Fedora FEDORA-2009-3720 2009-04-17
Red Hat RHSA-2009:0421-01 2009-04-14
Red Hat RHSA-2009:0420-01 2009-04-14
CentOS CESA-2009:0420 2009-04-15
Ubuntu USN-757-1 2009-04-15
Fedora FEDORA-2009-3435 2009-04-09
Fedora FEDORA-2009-3430 2009-04-09
Mandriva MDVSA-2009:096 2009-04-24
Mandriva MDVSA-2009:095 2009-04-24
CentOS CESA-2009:0421 2009-04-20
rPath rPSA-2009-0060-1 2009-04-17
Fedora FEDORA-2009-3709 2009-04-15
Fedora FEDORA-2009-3710 2009-04-15

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds