THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2020-36773

Assignermitre
Reserved2024-02-04
Published2024-02-04
Updated2024-07-05

Description

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

References

https://bugs.ghostscript.com/show_bug.cgi?id=702229

https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=8c7bd787defa071c96289b7da9397f673fddb874

https://bugzilla.opensuse.org/show_bug.cgi?id=1177922

https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/tag/gs9530

cve.org CVE-2020-36773

nvd.nist.gov CVE-2020-36773

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2020-36773
© Copyright 2024 THREATINT. Made in Cyprus with +