---
cve: "CVE-2012-4405"
severity: "LOW"
cvss: 3.1
epss: "7.5%"
vendor: "n/a"
kev: false
exploited: false
published: "2012-09-18 17:55:07"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T21:20:04+02:00"
---

# CVE-2012-4405

> 3.1 LOW

## Beschreibung

Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow.  NOTE: this issue is also described as an array index error.

## Referenzen

- <http://rhn.redhat.com/errata/RHSA-2012-1256.html>
- <http://security.gentoo.org/glsa/glsa-201412-17.xml>
- <https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0301>
- <http://www.openwall.com/lists/oss-security/2012/09/11/2>
- <http://lists.opensuse.org/opensuse-updates/2012-10/msg00015.html>
- <http://www.mandriva.com/security/advisories?name=MDVSA-2013:089>
- <http://www.mandriva.com/security/advisories?name=MDVSA-2013:090>
- <http://www.securityfocus.com/bid/55494>
- <http://secunia.com/advisories/50719>
- <http://lists.opensuse.org/opensuse-security-announce/2012-09/msg00031.html>
- <http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00001.html>
- <https://exchange.xforce.ibmcloud.com/vulnerabilities/78411>
- <http://www.securitytracker.com/id?1027517>
- <http://www.ubuntu.com/usn/USN-1581-1>
- <http://www.mandriva.com/security/advisories?name=MDVSA-2012:151>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2012-4405) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
