Lucene search

K
nvd[email protected]NVD:CVE-2009-0584
HistoryMar 23, 2009 - 8:00 p.m.

CVE-2009-0584

2009-03-2320:00:00
CWE-189
web.nvd.nist.gov
6

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

High

EPSS

0.008

Percentile

82.0%

icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device file for processing a crafted image file associated with large integer values for certain sizes, related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.

Affected configurations

Nvd
Node
argyllcmscmsRange≀1.0.3
OR
ghostscriptghostscriptRange≀8.64
OR
ghostscriptghostscriptMatch0
OR
ghostscriptghostscriptMatch5.50
OR
ghostscriptghostscriptMatch7.05
OR
ghostscriptghostscriptMatch7.07
OR
ghostscriptghostscriptMatch8.0.1
OR
ghostscriptghostscriptMatch8.15
OR
ghostscriptghostscriptMatch8.15.2
OR
ghostscriptghostscriptMatch8.54
OR
ghostscriptghostscriptMatch8.56
OR
ghostscriptghostscriptMatch8.57
OR
ghostscriptghostscriptMatch8.60
OR
ghostscriptghostscriptMatch8.61
VendorProductVersionCPE
argyllcmscms*cpe:2.3:a:argyllcms:cms:*:*:*:*:*:*:*:*
ghostscriptghostscript*cpe:2.3:a:ghostscript:ghostscript:*:*:*:*:*:*:*:*
ghostscriptghostscript0cpe:2.3:a:ghostscript:ghostscript:0:*:*:*:*:*:*:*
ghostscriptghostscript5.50cpe:2.3:a:ghostscript:ghostscript:5.50:*:*:*:*:*:*:*
ghostscriptghostscript7.05cpe:2.3:a:ghostscript:ghostscript:7.05:*:*:*:*:*:*:*
ghostscriptghostscript7.07cpe:2.3:a:ghostscript:ghostscript:7.07:*:*:*:*:*:*:*
ghostscriptghostscript8.0.1cpe:2.3:a:ghostscript:ghostscript:8.0.1:*:*:*:*:*:*:*
ghostscriptghostscript8.15cpe:2.3:a:ghostscript:ghostscript:8.15:*:*:*:*:*:*:*
ghostscriptghostscript8.15.2cpe:2.3:a:ghostscript:ghostscript:8.15.2:*:*:*:*:*:*:*
ghostscriptghostscript8.54cpe:2.3:a:ghostscript:ghostscript:8.54:*:*:*:*:*:*:*
Rows per page:
1-10 of 141

References

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

High

EPSS

0.008

Percentile

82.0%