CVE-2009-0584

NameCVE-2009-0584
Descriptionicc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-1746-1, DTSA-198-1
NVD severityhigh (attack range: remote, user-initiated)
Debian Bugs522416, 522448
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
argyll (PTS)squeeze1.1.1-1fixed
wheezy1.4.0-8fixed
jessie, sid1.6.3-4fixed
ghostscript (PTS)squeeze (security), squeeze8.71~dfsg2-9+squeeze1fixed
wheezy9.05~dfsg-6.3+deb7u1fixed
jessie, sid9.06~dfsg-2fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
argyllsource(unstable)1.0.3-2high522448
ghostscriptsource(unstable)8.64~dfsg-1.1medium522416
ghostscriptsourcelenny8.62.dfsg.1-3.2lenny1highDSA-1746-1
ghostscriptsourcesqueeze8.64~dfsg-1+squeeze1highDTSA-198-1
gs-espsource(unstable)(unfixed)high
gs-gplsource(unstable)(unfixed)medium
gs-gplsourceetch8.54.dfsg.1-5etch2highDSA-1746-1

Search for package or bug name: Reporting problems