CVE-2021-45949
published 2022-01-01CVE-2021-45949: Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-7+deb11u2 | 9.53.3~dfsg-7+deb11u2 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg-1 | 9.55.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg-1 | 9.55.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg-1 | 9.55.0~dfsg-1 |
| artifex | ghostscript | 9.50 – 9.54.0 | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | ghostscript | < ghostscript 9.55.0~dfsg-1 (bookworm) | ghostscript 9.55.0~dfsg-1 (bookworm) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM