CPANSA-Win32-Printer-2009-0583-jquery: Win32-Printer vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2009-03-23T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2009-03-23T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | Severity | ||
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
Vulnerabilities
CVE-2009-0583
Vulnerability DescriptionMultiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images.
| Weakness | CWE-119 : Improper Restriction of Operations within the Bounds of a Memory Buffer |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Win32-Printer greater than or equal 0.9.0 and less than or equal 0.9.1 |
|
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Win32-Printer-2009-0583-jquery JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2009/cpansa-win32-printer-2009-0583-jquery.json - http://secunia.com/advisories/34393 external
http://secunia.com/advisories/34393 - https://bugzilla.redhat.com/show_bug.cgi?id=487742 external
https://bugzilla.redhat.com/show_bug.cgi?id=487742 - http://www.redhat.com/support/errata/RHSA-2009-0345.html external
http://www.redhat.com/support/errata/RHSA-2009-0345.html - http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0050 external
http://wiki.rpath.com/wiki/Advisories:rPSA-2009-0050 - http://securitytracker.com/id?1021868 external
http://securitytracker.com/id?1021868 - https://issues.rpath.com/browse/RPL-2991 external
https://issues.rpath.com/browse/RPL-2991 - http://www.vupen.com/english/advisories/2009/0776 external
http://www.vupen.com/english/advisories/2009/0776 - https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00770.html external
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00770.html - http://secunia.com/advisories/34373 external
http://secunia.com/advisories/34373 - http://secunia.com/advisories/34398 external
http://secunia.com/advisories/34398 - http://www.debian.org/security/2009/dsa-1746 external
http://www.debian.org/security/2009/dsa-1746 - https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00772.html external
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00772.html - http://www.vupen.com/english/advisories/2009/0777 external
http://www.vupen.com/english/advisories/2009/0777 - http://secunia.com/advisories/34381 external
http://secunia.com/advisories/34381 - http://bugs.gentoo.org/show_bug.cgi?id=261087 external
http://bugs.gentoo.org/show_bug.cgi?id=261087 - http://www.auscert.org.au/render.html?it=10666 external
http://www.auscert.org.au/render.html?it=10666 - http://www.securityfocus.com/bid/34184 external
http://www.securityfocus.com/bid/34184 - http://www.gentoo.org/security/en/glsa/glsa-200903-37.xml external
http://www.gentoo.org/security/en/glsa/glsa-200903-37.xml - http://support.avaya.com/elmodocs2/security/ASA-2009-098.htm external
http://support.avaya.com/elmodocs2/security/ASA-2009-098.htm - http://secunia.com/advisories/34437 external
http://secunia.com/advisories/34437 - http://www.vupen.com/english/advisories/2009/0816 external
http://www.vupen.com/english/advisories/2009/0816 - http://www.ubuntu.com/usn/USN-743-1 external
http://www.ubuntu.com/usn/USN-743-1 - http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html external
http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html - http://secunia.com/advisories/34418 external
http://secunia.com/advisories/34418 - http://secunia.com/advisories/34266 external
http://secunia.com/advisories/34266 - https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00916.html external
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00916.html - http://secunia.com/advisories/34469 external
http://secunia.com/advisories/34469 - https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00887.html external
https://www.redhat.com/archives/fedora-package-announce/2009-March/msg00887.html - http://secunia.com/advisories/34443 external
http://secunia.com/advisories/34443 - http://secunia.com/advisories/34729 external
http://secunia.com/advisories/34729 - http://www.mandriva.com/security/advisories?name=MDVSA-2009:095 external
http://www.mandriva.com/security/advisories?name=MDVSA-2009:095 - http://www.mandriva.com/security/advisories?name=MDVSA-2009:096 external
http://www.mandriva.com/security/advisories?name=MDVSA-2009:096 - http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1 external
http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1 - http://www.vupen.com/english/advisories/2009/1708 external
http://www.vupen.com/english/advisories/2009/1708 - http://secunia.com/advisories/35569 external
http://secunia.com/advisories/35569 - http://secunia.com/advisories/35559 external
http://secunia.com/advisories/35559 - https://exchange.xforce.ibmcloud.com/vulnerabilities/49329 external
https://exchange.xforce.ibmcloud.com/vulnerabilities/49329 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10795 external
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10795 - https://usn.ubuntu.com/757-1/ external
https://usn.ubuntu.com/757-1/ - http://www.securityfocus.com/archive/1/501994/100/0/threaded external
http://www.securityfocus.com/archive/1/501994/100/0/threaded - CVE-2009-0583 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2009-0583
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Mon Mar 23 00:00:00 2009 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/