Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2009-0792 | First vendor Publication | 2009-04-14 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0792 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-189 | Numeric Errors (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:11207 | |||
Oval ID: | oval:org.mitre.oval:def:11207 | ||
Title: | Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583. | ||
Description: | Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583. | ||
Family: | unix | Class: | vulnerability |
Reference(s): | CVE-2009-0792 | Version: | 5 |
Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 | Product(s): | |
Definition Synopsis: | |||
|
Definition Id: oval:org.mitre.oval:def:22480 | |||
Oval ID: | oval:org.mitre.oval:def:22480 | ||
Title: | ELSA-2009:0421: ghostscript security update (Moderate) | ||
Description: | Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583. | ||
Family: | unix | Class: | patch |
Reference(s): | ELSA-2009:0421-01 CVE-2007-6725 CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 | Version: | 21 |
Platform(s): | Oracle Linux 5 | Product(s): | ghostscript |
Definition Synopsis: | |||
Definition Id: oval:org.mitre.oval:def:29276 | |||
Oval ID: | oval:org.mitre.oval:def:29276 | ||
Title: | RHSA-2009:0421 -- ghostscript security update (Moderate) | ||
Description: | Updated ghostscript packages that fix multiple security issues are now available for Red Hat Enterprise Linux 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. Ghostscript is a set of software that provides a PostScript interpreter, a set of C procedures (the Ghostscript library, which implements the graphics capabilities in the PostScript language) and an interpreter for Portable Document Format (PDF) files. | ||
Family: | unix | Class: | patch |
Reference(s): | RHSA-2009:0421 CESA-2009:0421-CentOS 5 CVE-2007-6725 CVE-2008-6679 CVE-2009-0196 CVE-2009-0792 | Version: | 3 |
Platform(s): | Red Hat Enterprise Linux 5 CentOS Linux 5 | Product(s): | ghostscript |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2011-08-09 | Name : CentOS Update for ghostscript CESA-2009:0420 centos3 i386 File : nvt/gb_CESA-2009_0420_ghostscript_centos3_i386.nasl |
2011-08-09 | Name : CentOS Update for ghostscript CESA-2009:0420 centos4 i386 File : nvt/gb_CESA-2009_0420_ghostscript_centos4_i386.nasl |
2011-08-09 | Name : CentOS Update for ghostscript CESA-2009:0421 centos5 i386 File : nvt/gb_CESA-2009_0421_ghostscript_centos5_i386.nasl |
2010-08-21 | Name : Debian Security Advisory DSA 2080-1 (ghostscript) File : nvt/deb_2080_1.nasl |
2009-12-10 | Name : Mandriva Security Advisory MDVSA-2009:311 (ghostscript) File : nvt/mdksa_2009_311.nasl |
2009-10-13 | Name : SLES10: Security update for GhostScript File : nvt/sles10_ghostscript-fon.nasl |
2009-10-13 | Name : Solaris Update for Ghostscript 115835-05 File : nvt/gb_solaris_115835_05.nasl |
2009-10-13 | Name : Solaris Update for Ghostscript 115836-05 File : nvt/gb_solaris_115836_05.nasl |
2009-10-11 | Name : SLES11: Security update for GhostScript File : nvt/sles11_ghostscript-fon1.nasl |
2009-10-11 | Name : SLES11: Security update for Ghostscript File : nvt/sles11_ghostscript-fon0.nasl |
2009-10-10 | Name : SLES9: Security update for GhostScript File : nvt/sles9p5049760.nasl |
2009-09-23 | Name : Solaris Update for SunFreeware ghostscript man pages 122262-02 File : nvt/gb_solaris_122262_02.nasl |
2009-09-23 | Name : Solaris Update for SunFreeware ghostscript man pages 122261-02 File : nvt/gb_solaris_122261_02.nasl |
2009-09-23 | Name : Solaris Update for SunFreeware gnu esp ghostscript 122260-02 File : nvt/gb_solaris_122260_02.nasl |
2009-09-23 | Name : Solaris Update for SunFreeware gnu esp ghostscript 122259-02 File : nvt/gb_solaris_122259_02.nasl |
2009-06-15 | Name : SuSE Security Summary SUSE-SR:2009:011 File : nvt/suse_sr_2009_011.nasl |
2009-05-25 | Name : CentOS Security Advisory CESA-2009:0420 (ghostscript) File : nvt/ovcesa2009_0420.nasl |
2009-05-05 | Name : Mandrake Security Advisory MDVSA-2009:096-1 (printer-drivers) File : nvt/mdksa_2009_096_1.nasl |
2009-04-28 | Name : Ghostscript Multiple Buffer Overflow Vulnerabilities (Linux) File : nvt/secpod_ghostscript_mult_bof_vuln_lin.nasl |
2009-04-28 | Name : Ghostscript Multiple Buffer Overflow Vulnerabilities (Win) File : nvt/secpod_ghostscript_mult_bof_vuln_win.nasl |
2009-04-28 | Name : SuSE Security Summary SUSE-SR:2009:009 File : nvt/suse_sr_2009_009.nasl |
2009-04-28 | Name : Mandrake Security Advisory MDVSA-2009:095 (ghostscript) File : nvt/mdksa_2009_095.nasl |
2009-04-28 | Name : Mandrake Security Advisory MDVSA-2009:096 (printer-drivers) File : nvt/mdksa_2009_096.nasl |
2009-04-20 | Name : Ubuntu USN-757-1 (gs-gpl) File : nvt/ubuntu_757_1.nasl |
2009-04-20 | Name : Fedora Core 10 FEDORA-2009-3740 (argyllcms) File : nvt/fcore_2009_3740.nasl |
2009-04-20 | Name : Fedora Core 9 FEDORA-2009-3720 (argyllcms) File : nvt/fcore_2009_3720.nasl |
2009-04-20 | Name : Fedora Core 9 FEDORA-2009-3710 (ghostscript) File : nvt/fcore_2009_3710.nasl |
2009-04-20 | Name : Fedora Core 10 FEDORA-2009-3709 (ghostscript) File : nvt/fcore_2009_3709.nasl |
2009-04-15 | Name : Fedora Core 10 FEDORA-2009-3435 (argyllcms) File : nvt/fcore_2009_3435.nasl |
2009-04-15 | Name : Fedora Core 9 FEDORA-2009-3430 (argyllcms) File : nvt/fcore_2009_3430.nasl |
2009-04-15 | Name : RedHat Security Advisory RHSA-2009:0421 File : nvt/RHSA_2009_0421.nasl |
2009-04-15 | Name : RedHat Security Advisory RHSA-2009:0420 File : nvt/RHSA_2009_0420.nasl |
0000-00-00 | Name : Slackware Advisory SSA:2009-181-01 ghostscript File : nvt/esoft_slk_ssa_2009_181_01.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
56412 | International Color Consortium (ICC) Format library (icclib) Native Color Spa... |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2014-12-15 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201412-17.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2009-0421.nasl - Type : ACT_GATHER_INFO |
2013-07-12 | Name : The remote Oracle Linux host is missing one or more security updates. File : oraclelinux_ELSA-2009-0420.nasl - Type : ACT_GATHER_INFO |
2012-08-01 | Name : The remote Scientific Linux host is missing one or more security updates. File : sl_20090414_ghostscript_on_SL3_x.nasl - Type : ACT_GATHER_INFO |
2010-08-03 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-2080.nasl - Type : ACT_GATHER_INFO |
2010-01-06 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2009-0421.nasl - Type : ACT_GATHER_INFO |
2009-12-04 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2009-311.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 10 host is missing a security-related patch. File : suse_ghostscript-fonts-other-6245.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_ghostscript-devel-090513.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 11 host is missing one or more security updates. File : suse_11_ghostscript-devel-090407.nasl - Type : ACT_GATHER_INFO |
2009-09-24 | Name : The remote SuSE 9 host is missing a security-related patch. File : suse9_12417.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_1_ghostscript-devel-090514.nasl - Type : ACT_GATHER_INFO |
2009-07-21 | Name : The remote openSUSE host is missing a security update. File : suse_11_0_ghostscript-devel-090513.nasl - Type : ACT_GATHER_INFO |
2009-06-30 | Name : The remote Slackware host is missing a security update. File : Slackware_SSA_2009-181-01.nasl - Type : ACT_GATHER_INFO |
2009-05-18 | Name : The remote openSUSE host is missing a security update. File : suse_ghostscript-devel-6246.nasl - Type : ACT_GATHER_INFO |
2009-04-27 | Name : The remote Mandriva Linux host is missing one or more security updates. File : mandriva_MDVSA-2009-095.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Ubuntu host is missing one or more security-related patches. File : ubuntu_USN-757-1.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Fedora host is missing a security update. File : fedora_2009-3740.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Fedora host is missing a security update. File : fedora_2009-3709.nasl - Type : ACT_GATHER_INFO |
2009-04-23 | Name : The remote Fedora host is missing a security update. File : fedora_2009-3435.nasl - Type : ACT_GATHER_INFO |
2009-04-21 | Name : The remote Fedora host is missing a security update. File : fedora_2009-3720.nasl - Type : ACT_GATHER_INFO |
2009-04-16 | Name : The remote Fedora host is missing a security update. File : fedora_2009-3710.nasl - Type : ACT_GATHER_INFO |
2009-04-15 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2009-0420.nasl - Type : ACT_GATHER_INFO |
2009-04-15 | Name : The remote CentOS host is missing one or more security updates. File : centos_RHSA-2009-0420.nasl - Type : ACT_GATHER_INFO |
2009-04-15 | Name : The remote Red Hat host is missing one or more security updates. File : redhat-RHSA-2009-0421.nasl - Type : ACT_GATHER_INFO |
2009-04-10 | Name : The remote Fedora host is missing a security update. File : fedora_2009-3430.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:11:36 |
|
2024-11-28 12:18:26 |
|
2023-11-07 21:47:44 |
|
2023-02-13 09:29:20 |
|
2021-05-05 01:05:45 |
|
2021-05-04 12:09:13 |
|
2021-04-22 01:09:34 |
|
2020-05-24 01:05:37 |
|
2020-05-23 01:40:07 |
|
2020-05-23 00:23:27 |
|
2018-10-11 00:19:32 |
|
2018-10-04 00:19:35 |
|
2017-09-29 09:24:06 |
|
2017-08-17 09:22:29 |
|
2016-04-26 18:40:45 |
|
2015-01-07 09:24:04 |
|
2014-12-16 13:24:30 |
|
2014-02-17 10:49:05 |
|
2013-05-10 23:45:30 |
|