CVE-2020-36773
published 2024-02-04CVE-2020-36773: Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in…
PriorityP346critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.88%
55.3th percentile
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | — | — |
| artifex | ghostscript | — | — |
| artifex | ghostscript | — | — |
| artifex | ghostscript | — | — |
| artifex | ghostscript | >= 0 < 9.53.0~dfsg-1 | 9.53.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.53.0~dfsg-1 | 9.53.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.53.0~dfsg-1 | 9.53.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.53.0~dfsg-1 | 9.53.0~dfsg-1 |
| debian | ghostscript | < ghostscript 9.53.0~dfsg-1 (bookworm) | ghostscript 9.53.0~dfsg-1 (bookworm) |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Ghostscript: out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite)
vendor_redhat·2024-02-04·CVSS 9.8
CVE-2020-36773 [CRITICAL] CWE-416 Ghostscript: out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite)
Ghostscript: out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite)
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
An out-of-bounds write, and a use-after-free flaw was found in Ghostscript. The flaw is present in devices/vector/gdevtxtw.c, for txtwrite, due to a single character code in a PDF document that can map to more than one Unicode code point (for example, a ligature).
Statement: The identified vulnerability in Ghostscript introduced in version 9.50 and FIxed in 9.53.0, this represents a important security issue due to its potential for exploitation by malicio
Debian
CVE-2020-36773: ghostscript - Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free ...
vendor_debian·2020·CVSS 9.8
CVE-2020-36773 [CRITICAL] CVE-2020-36773: ghostscript - Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free ...
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
Scope: local
bookworm: resolved (fixed in 9.53.0~dfsg-1)
bullseye: resolved (fixed in 9.53.0~dfsg-1)
forky: resolved (fixed in 9.53.0~dfsg-1)
sid: resolved (fixed in 9.53.0~dfsg-1)
trixie: resolved (fixed in 9.53.0~dfsg-1)
OSV
CVE-2020-36773: Artifex Ghostscript before 9
osv·2024-02-04·CVSS 9.8
CVE-2020-36773 [CRITICAL] CVE-2020-36773: Artifex Ghostscript before 9
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
GHSA
GHSA-mwx2-8cmg-6vmj: Artifex Ghostscript before 9
ghsa_unreviewed·2024-02-04
CVE-2020-36773 [CRITICAL] CWE-416 GHSA-mwx2-8cmg-6vmj: Artifex Ghostscript before 9
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.ghostscript.com/show_bug.cgi?id=702229https://bugzilla.opensuse.org/show_bug.cgi?id=1177922https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=8c7bd787defa071c96289b7da9397f673fddb874https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/tag/gs9530https://bugs.ghostscript.com/show_bug.cgi?id=702229https://bugzilla.opensuse.org/show_bug.cgi?id=1177922https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=8c7bd787defa071c96289b7da9397f673fddb874https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/tag/gs9530
2024-02-04
Published