ubuntu · CVE-2012-4405

Quick triage

Priority: medium Published: 2012-09-18 00:00:00 UTC Updated: 2025-08-04 19:24:15 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2012-4405 medium priority: Ubuntu including 5 source packages (argyll, ghostscript, gs-afpl, gs-esp, gs-gpl), 80 status rows across 16 suites (hardy, lucid, natty, oneiric, precise, quantal, raring, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): DNE 48, not-affected 21, ignored 4, needs-triage 4, released 3.

Description:

Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error.

cvelogic Threat Intelligence