File _patchinfo of Package patchinfo.883
<patchinfo incident="883"> <packager>jsmeix</packager> <issue tracker="cve" id="CVE-2012-4405"></issue> <issue tracker="bnc" id="779700"></issue> <category>security</category> <rating>low</rating> <summary>ghostscript-library: security bugfix release</summary> <description>The following security issue was fixed in ghostscript: Multiple integer underflows in the icmLut_allocate function in International Color Consortium (ICC) Format library (icclib), as used in Ghostscript 9.06 and Argyll Color Management System, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PostScript or (2) PDF file with embedded images, which triggers a heap-based buffer overflow. NOTE: this issue is also described as an array index error. </description> </patchinfo>