CVE-2012-4405
ghostscript - buffer overflow
EPSS 23.8%
Description
Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error.
How to fix CVE-2012-4405
To remediate CVE-2012-4405, upgrade the affected package to a fixed version below.
- Debian/argyll—upgrade to 1.4.0-7 or later
- —upgrade to 9.05~dfsg-6.1 or later
- —upgrade to 8.71~dfsg2-9+squeeze1 or later
Is CVE-2012-4405 being exploited?
Moderate — EPSS is 23.8%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (3)
- from 0, < 1.4.0-7
- from 0, < 9.05~dfsg-6.1
- from 0, < 8.71~dfsg2-9+squeeze1