Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-36773

Опубликовано: 04 фев. 2024
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:artifex:ghostscript:9.51:*:*:*:*:*:*:*
cpe:2.3:a:artifex:ghostscript:9.52:*:*:*:*:*:*:*
cpe:2.3:a:artifex:ghostscript:9.52.1:*:*:*:*:*:*:*
cpe:2.3:a:artifex:ghostscript:9.53.0:rc1:*:*:*:*:*:*
cpe:2.3:a:artifex:ghostscript:9.53.0:rc2:*:*:*:*:*:*

EPSS

Процентиль: 29%
0.00106
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-416
CWE-416

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 2 лет назад

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

CVSS3: 9.8
redhat
около 2 лет назад

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

CVSS3: 9.8
debian
около 2 лет назад

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-a ...

suse-cvrf
почти 2 года назад

Security update for ghostscript

suse-cvrf
почти 2 года назад

Security update for ghostscript

EPSS

Процентиль: 29%
0.00106
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-416
CWE-416