CVE-2009-0792
Summary
| CVE | CVE-2009-0792 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-04-14 16:26:56 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:M/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Argyllcms | Argyllcms | 0.1.0 | All | All | All |
| Application | Argyllcms | Argyllcms | 0.2.0 | All | All | All |
| Application | Argyllcms | Argyllcms | 0.2.1 | All | All | All |
| Application | Argyllcms | Argyllcms | 0.2.2 | All | All | All |
| Application | Argyllcms | Argyllcms | 0.3.0 | All | All | All |
| Application | Argyllcms | Argyllcms | 0.6.0 | All | All | All |
| Application | Argyllcms | Argyllcms | 0.7.0 | beta_8 | All | All |
| Application | Argyllcms | Argyllcms | 1.0.0 | All | All | All |
| Application | Argyllcms | Argyllcms | 1.0.2 | All | All | All |
| Application | Argyllcms | Argyllcms | All | All | All | All |
| Application | Ghostscript | Ghostscript | 5.50 | All | All | All |
| Application | Ghostscript | Ghostscript | 7.05 | All | All | All |
| Application | Ghostscript | Ghostscript | 7.07 | All | All | All |
| Application | Ghostscript | Ghostscript | 8.0.1 | All | All | All |
| Application | Ghostscript | Ghostscript | 8.15 | All | All | All |
| Application | Ghostscript | Ghostscript | 8.15.2 | All | All | All |
| Application | Ghostscript | Ghostscript | 8.54 | All | All | All |
| Application | Ghostscript | Ghostscript | 8.56 | All | All | All |
| Application | Ghostscript | Ghostscript | 8.57 | All | All | All |
| Application | Ghostscript | Ghostscript | 8.61 | All | All | All |
| Application | Ghostscript | Ghostscript | 8.62 | All | All | All |
| Application | Ghostscript | Ghostscript | 8.63 | All | All | All |
| Application | Ghostscript | Ghostscript | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Support / Security / Advisories / / MDVSA-2009:095 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| [SECURITY] Fedora 10 Update: ghostscript-8.63-6.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Argyll Color Management System icclib Multiple Vulnerabilities - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Fedora update for ghostscript - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat update for ghostscript - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Ubuntu update for ghostscript - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Gentoo Linux Documentation -- GPL Ghostscript: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| ASA-2009-155 (RHSA-2009-0420) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:011 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Sun Solaris 9 Ghostscript Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| USN-757-1: Ghostscript vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| wiki.rpath.com/Advisories:rPSA-2009-0060 | af854a3a-2127-422b-91ae-364da2661108 | wiki.rpath.com | |
| [SECURITY] Fedora 10 Update: argyllcms-1.0.3-4.fc10 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| 491853 – (CVE-2009-0792) CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583 | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Fedora update for argyllcms - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Support / Security / Advisories / / MDVSA-2009:096 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| Sun Solaris Ghostscript Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail | OVH- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [SECURITY] Fedora 9 Update: ghostscript-8.63-3.fc9 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [SECURITY] Fedora 9 Update: argyllcms-1.0.3-4.fc9 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2009:009 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| SUSE Update for Multiple Packages - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Red Hat update for ghostscript - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.