CVE-2021-45949
published 2022-01-01CVE-2021-45949: Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.40%
69.5th percentile
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-7+deb11u2 | 9.53.3~dfsg-7+deb11u2 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg-1 | 9.55.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg-1 | 9.55.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg-1 | 9.55.0~dfsg-1 |
| artifex | ghostscript | 9.50 – 9.54.0 | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ghostscript | < ghostscript 9.55.0~dfsg-1 (bookworm) | ghostscript 9.55.0~dfsg-1 (bookworm) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2022-01-13
CVE-2021-45944 Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
USN-5224-1 fixed several vulnerabilities in Ghostscript. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that Ghostscript incorrectly handled certain PostScript
files. If a user or automated system were tricked into processing a
specially crafted file, a remote attacker could possibly use this issue to
cause Ghostscript to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2022-01-12
CVE-2021-45944 Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript incorrectly handled certain PostScript
files. If a user or automated system were tricked into processing a
specially crafted file, a remote attacker could possibly use this issue to
cause Ghostscript to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ghostscript: heap-based buffer overflow in sampled_data_finish
vendor_redhat·2022-01-01·CVSS 5.5
CVE-2021-45949 [MEDIUM] CWE-787 ghostscript: heap-based buffer overflow in sampled_data_finish
ghostscript: heap-based buffer overflow in sampled_data_finish
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
A heap-based buffer overflow flaw was found in Ghostscript’s GhostPDL in the sampled_data_finish function (called from sampled_data_continue and interp). This flaw allows a local attacker to pass a specially crafted malicious file to Ghostscript that triggers a heap-based buffer overflow, potentially causing a crash that leads to a denial of service.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact and the issue is not currently planned to be addressed in future updates for Red Hat Enterprise Linux 6 and 7, hence, marked as Out-of-Support-S
Debian
CVE-2021-45949: ghostscript - Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sam...
vendor_debian·2021·CVSS 5.5
CVE-2021-45949 [MEDIUM] CVE-2021-45949: ghostscript - Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sam...
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
Scope: local
bookworm: resolved (fixed in 9.55.0~dfsg-1)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u2)
forky: resolved (fixed in 9.55.0~dfsg-1)
sid: resolved (fixed in 9.55.0~dfsg-1)
trixie: resolved (fixed in 9.55.0~dfsg-1)
GHSA
GHSA-r647-qm87-j9pc: Ghostscript GhostPDL 9
ghsa_unreviewed·2022-01-02
CVE-2021-45949 [MEDIUM] CWE-787 GHSA-r647-qm87-j9pc: Ghostscript GhostPDL 9
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
OSV
CVE-2021-45949: Ghostscript GhostPDL 9
osv·2022-01-01·CVSS 5.5
CVE-2021-45949 [MEDIUM] CVE-2021-45949: Ghostscript GhostPDL 9
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=34675https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=2a3129365d3bc0d4a41f107ef175920d1505d1f7https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-803.yamlhttps://lists.debian.org/debian-lts-announce/2022/01/msg00006.htmlhttps://www.debian.org/security/2022/dsa-5038https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=34675https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=2a3129365d3bc0d4a41f107ef175920d1505d1f7https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-803.yamlhttps://lists.debian.org/debian-lts-announce/2022/01/msg00006.htmlhttps://www.debian.org/security/2022/dsa-5038
2022-01-01
Published