CPANSA-Win32-Printer-2009-0792-jquery: Win32-Printer vulnerability
| Publisher | giterlizzi | Document category | csaf_security_advisory |
|---|---|---|---|
| Initial release date | 2009-04-14T00:00:00 | Engine | CSAF Perl Toolkit 0.26 |
| Current release date | 2009-04-14T00:00:00 | Build Date | |
| Current version | 1 | Status | final |
| CVSS v3.1 Base Score | Severity | ||
| Original language | Language | en | |
| Also referred to | |||
Vulnerability Description
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
Vulnerabilities
CVE-2009-0792
Vulnerability DescriptionMultiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code by using a device file for a translation request that operates on a crafted image file and targets a certain "native color space," related to an ICC profile in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue exists because of an incomplete fix for CVE-2009-0583.
| Weakness | CWE-189 : Numeric Errors |
|---|
Product status
Known affected
| Product | Score | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Win32-Printer greater than or equal 0.9.0 and less than or equal 0.9.1 |
|
giterlizzi
Namespace: https://github.com/giterlizzi/
gdt@cpan.org
References
- CPANSA-Win32-Printer-2009-0792-jquery JSON self
https://raw.githubusercontent.com/giterlizzi/perl-CPANSA-CSAF/develop/csaf/white/2009/cpansa-win32-printer-2009-0792-jquery.json - https://bugzilla.redhat.com/show_bug.cgi?id=491853 external
https://bugzilla.redhat.com/show_bug.cgi?id=491853 - http://secunia.com/advisories/34711 external
http://secunia.com/advisories/34711 - http://secunia.com/advisories/34373 external
http://secunia.com/advisories/34373 - https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00211.html external
https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00211.html - https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00217.html external
https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00217.html - http://www.redhat.com/support/errata/RHSA-2009-0420.html external
http://www.redhat.com/support/errata/RHSA-2009-0420.html - http://secunia.com/advisories/34726 external
http://secunia.com/advisories/34726 - http://secunia.com/advisories/34732 external
http://secunia.com/advisories/34732 - http://www.redhat.com/support/errata/RHSA-2009-0421.html external
http://www.redhat.com/support/errata/RHSA-2009-0421.html - https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00460.html external
https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00460.html - http://secunia.com/advisories/34667 external
http://secunia.com/advisories/34667 - http://wiki.rpath.com/Advisories:rPSA-2009-0060 external
http://wiki.rpath.com/Advisories:rPSA-2009-0060 - http://secunia.com/advisories/34729 external
http://secunia.com/advisories/34729 - https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00461.html external
https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00461.html - http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html external
http://lists.opensuse.org/opensuse-security-announce/2009-04/msg00010.html - http://www.mandriva.com/security/advisories?name=MDVSA-2009:096 external
http://www.mandriva.com/security/advisories?name=MDVSA-2009:096 - http://www.mandriva.com/security/advisories?name=MDVSA-2009:095 external
http://www.mandriva.com/security/advisories?name=MDVSA-2009:095 - http://support.avaya.com/elmodocs2/security/ASA-2009-155.htm external
http://support.avaya.com/elmodocs2/security/ASA-2009-155.htm - http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html external
http://lists.opensuse.org/opensuse-security-announce/2009-06/msg00003.html - http://secunia.com/advisories/35416 external
http://secunia.com/advisories/35416 - http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1 external
http://sunsolve.sun.com/search/document.do?assetkey=1-26-262288-1 - http://www.vupen.com/english/advisories/2009/1708 external
http://www.vupen.com/english/advisories/2009/1708 - http://secunia.com/advisories/35559 external
http://secunia.com/advisories/35559 - http://secunia.com/advisories/35569 external
http://secunia.com/advisories/35569 - http://security.gentoo.org/glsa/glsa-201412-17.xml external
http://security.gentoo.org/glsa/glsa-201412-17.xml - https://exchange.xforce.ibmcloud.com/vulnerabilities/50381 external
https://exchange.xforce.ibmcloud.com/vulnerabilities/50381 - https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11207 external
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11207 - https://usn.ubuntu.com/757-1/ external
https://usn.ubuntu.com/757-1/ - http://www.securityfocus.com/archive/1/502757/100/0/threaded external
http://www.securityfocus.com/archive/1/502757/100/0/threaded - CVE-2009-0792 (NVD) external
https://nvd.nist.gov/vuln/detail/CVE-2009-0792
Revision history
| Version | Date of the revision | Summary of the revision |
|---|---|---|
| 1 | Tue Apr 14 00:00:00 2009 | First release |
Sharing rules
TLP:WHITE
For the TLP version see: https://www.first.org/tlp/