---
title: "CVE-2009-0792\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2009-0792?format=md
keywords: index, follow
---

# CVE-2009-0792

Publication date 14 April 2009

Last updated 4 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Multiple integer overflows in icc.c in the International Color Consortium
(ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier
and Argyll Color Management System (CMS) 1.0.3 and earlier, allow
context-dependent attackers to cause a denial of service (heap-based buffer
overflow and application crash) or possibly execute arbitrary code by using
a device file for a translation request that operates on a crafted image
file and targets a certain "native color space," related to an ICC profile
in a (1) PostScript or (2) PDF file with embedded images. NOTE: this issue
exists because of an incomplete fix for CVE-2009-0583.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| ghostscript | 9.10 karmic | Fixed 8.64.dfsg.1-0ubuntu8 |
| 9.04 jaunty | Fixed 8.64.dfsg.1-0ubuntu8 |
| 8.10 intrepid | Fixed 8.63.dfsg.1-0ubuntu6.4 |
| 8.04 LTS hardy | Fixed 8.61.dfsg.1-1ubuntu3.2 |
| 7.10 gutsy | Ignored end of life, was needed |
| 6.06 LTS dapper | Not in release |
| gs-afpl | 9.10 karmic | Not in release |
| 9.04 jaunty | Not in release |
| 8.10 intrepid | Not in release |
| 8.04 LTS hardy | Not in release |
| 7.10 gutsy | Not in release |
| 6.06 LTS dapper | Ignored end of life |
| gs-esp | 9.10 karmic | Not in release |
| 9.04 jaunty | Not in release |
| 8.10 intrepid | Not in release |
| 8.04 LTS hardy | Not in release |
| 7.10 gutsy | Not in release |
| 6.06 LTS dapper | Fixed 8.15.2.dfsg.0ubuntu1-0ubuntu1.2 |
| gs-gpl | 9.10 karmic | Not in release |
| 9.04 jaunty | Not in release |
| 8.10 intrepid | Not in release |
| 8.04 LTS hardy | Not in release |
| 7.10 gutsy | Not in release |
| 6.06 LTS dapper | Fixed 8.15-4ubuntu3.3 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0792)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2009-0792)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2009-0792)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2009-0792)

### Related Ubuntu Security Notices (USN)

+ [USN-757-1](https://usn.ubuntu.com/USN-757-1)
+ Ghostscript vulnerabilities
+ 15 April 2009

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2009-0792>
