Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-36773

Опубликовано: 04 фев. 2024
Источник: debian
EPSS Низкий

Описание

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ghostscriptfixed9.53.0~dfsg-1package
ghostscriptnot-affectedbusterpackage

Примечания

  • https://bugs.ghostscript.com/show_bug.cgi?id=702229

  • Fixed by: http://www.ghostscript.com/cgi-bin/findgit.cgi?8c7bd787defa071c96289b7da9397f673fddb874 (ghostpdl-9.53.0rc1)

EPSS

Процентиль: 29%
0.00106
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 лет назад

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

CVSS3: 9.8
redhat
около 2 лет назад

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

CVSS3: 9.8
nvd
около 2 лет назад

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

suse-cvrf
почти 2 года назад

Security update for ghostscript

suse-cvrf
почти 2 года назад

Security update for ghostscript

EPSS

Процентиль: 29%
0.00106
Низкий