Lucene search

K
osvGoogleOSV:DSA-1746-1
HistoryMar 20, 2009 - 12:00 a.m.

ghostscript gs-gpl - arbitrary code execution

2009-03-2000:00:00
Google
osv.dev
12

EPSS

0.01

Percentile

83.6%

Two security issues have been discovered in ghostscript, the GPL
Ghostscript PostScript/PDF interpreter. The Common Vulnerabilities and
Exposures project identifies the following problems:

  • CVE-2009-0583
    Jan Lieskovsky discovered multiple integer overflows in the ICC library,
    which allow the execution of arbitrary code via crafted ICC profiles in
    PostScript files with embedded images.
  • CVE-2009-0584
    Jan Lieskovsky discovered insufficient upper-bounds checks on certain
    variable sizes in the ICC library, which allow the execution of
    arbitrary code via crafted ICC profiles in PostScript files with
    embedded images.

For the stable distribution (lenny), these problems have been fixed in
version 8.62.dfsg.1-3.2lenny1.

For the oldstable distribution (etch), these problems have been fixed
in version 8.54.dfsg.1-5etch2. Please note that the package in oldstable
is called gs-gpl.

For the testing distribution (squeeze) and the unstable distribution
(sid), these problems will be fixed soon.

We recommend that you upgrade your ghostscript/gs-gpl packages.