We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2020-36773



Assignermitre
Reserved2024-02-04
Published2024-02-04
Updated2024-08-04

Description

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

References

https://bugs.ghostscript.com/show_bug.cgi?id=702229

https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=8c7bd787defa071c96289b7da9397f673fddb874

https://bugzilla.opensuse.org/show_bug.cgi?id=1177922

https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/tag/gs9530

cve.org CVE-2020-36773

nvd.nist.gov CVE-2020-36773

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.