Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mwx2-8cmg-6vmj

Опубликовано: 04 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

EPSS

Процентиль: 29%
0.00106
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-416

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 лет назад

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

CVSS3: 9.8
redhat
около 2 лет назад

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

CVSS3: 9.8
nvd
около 2 лет назад

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

CVSS3: 9.8
debian
около 2 лет назад

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-a ...

suse-cvrf
почти 2 года назад

Security update for ghostscript

EPSS

Процентиль: 29%
0.00106
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-416