CVE-2021-45944
published 2022-01-01CVE-2021-45944: Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.36%
68.6th percentile
Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-7+deb11u2 | 9.53.3~dfsg-7+deb11u2 |
| artifex | ghostscript | >= 0 < 9.54.0~dfsg-5 | 9.54.0~dfsg-5 |
| artifex | ghostscript | >= 0 < 9.54.0~dfsg-5 | 9.54.0~dfsg-5 |
| artifex | ghostscript | >= 0 < 9.54.0~dfsg-5 | 9.54.0~dfsg-5 |
| artifex | ghostscript | 9.50 – 9.53.3 | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ghostscript | < ghostscript 9.54.0~dfsg-5 (bookworm) | ghostscript 9.54.0~dfsg-5 (bookworm) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9mw4-q4wg-7hwh: Ghostscript GhostPDL 9
ghsa_unreviewed·2022-01-02
CVE-2021-45944 [MEDIUM] CWE-416 GHSA-9mw4-q4wg-7hwh: Ghostscript GhostPDL 9
Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
OSV
CVE-2021-45944: Ghostscript GhostPDL 9
osv·2022-01-01·CVSS 5.5
CVE-2021-45944 [MEDIUM] CVE-2021-45944: Ghostscript GhostPDL 9
Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2022-01-13
CVE-2021-45944 Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
USN-5224-1 fixed several vulnerabilities in Ghostscript. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Ghostscript incorrectly handled certain PostScript
files. If a user or automated system were tricked into processing a
specially crafted file, a remote attacker could possibly use this issue to
cause Ghostscript to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2022-01-12
CVE-2021-45944 Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript incorrectly handled certain PostScript
files. If a user or automated system were tricked into processing a
specially crafted file, a remote attacker could possibly use this issue to
cause Ghostscript to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ghostscript: use-after-free in sampled_data_sample may lead to DoS
vendor_redhat·2022-01-01·CVSS 5.5
CVE-2021-45944 [MEDIUM] CWE-416 ghostscript: use-after-free in sampled_data_sample may lead to DoS
ghostscript: use-after-free in sampled_data_sample may lead to DoS
Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
A heap-use-after-free flaw was found in Ghostscript’s GhostPDL in the sampled_data_sample function (called from sampled_data_continue and interp). This flaw allows a local attacker to pass a specially crafted malicious file to Ghostscript that triggers a heap-use-after-free issue, potentially causing a crash that leads to a denial of service.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact and the issue is not currently planned to be addressed in future updates for Red Hat Enterprise Linux 6 and 7, hence, marked as Out-of-Support-Scope. For additi
Debian
CVE-2021-45944: ghostscript - Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sa...
vendor_debian·2021·CVSS 5.5
CVE-2021-45944 [MEDIUM] CVE-2021-45944: ghostscript - Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sa...
Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
Scope: local
bookworm: resolved (fixed in 9.54.0~dfsg-5)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u2)
forky: resolved (fixed in 9.54.0~dfsg-5)
sid: resolved (fixed in 9.54.0~dfsg-5)
trixie: resolved (fixed in 9.54.0~dfsg-5)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=29903https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=30715https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=7861fcad13c497728189feafb41cd57b5b50ea25https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-237.yamlhttps://github.com/google/oss-fuzz-vulns/issues/16https://lists.debian.org/debian-lts-announce/2022/01/msg00006.htmlhttps://www.debian.org/security/2022/dsa-5038https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=29903https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=30715https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=7861fcad13c497728189feafb41cd57b5b50ea25https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-237.yamlhttps://github.com/google/oss-fuzz-vulns/issues/16https://lists.debian.org/debian-lts-announce/2022/01/msg00006.htmlhttps://www.debian.org/security/2022/dsa-5038
2022-01-01
Published