Vulnerability Description
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Artifex | Ghostscript | 9.51 |
Related Weaknesses (CWE)
References
- https://bugs.ghostscript.com/show_bug.cgi?id=702229Issue TrackingPatch
- https://bugzilla.opensuse.org/show_bug.cgi?id=1177922Issue Tracking
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=8c7bd787defa071c96289Broken Link
- https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/tag/gs9530Release Notes
- https://bugs.ghostscript.com/show_bug.cgi?id=702229Issue TrackingPatch
- https://bugzilla.opensuse.org/show_bug.cgi?id=1177922Issue Tracking
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=8c7bd787defa071c96289Broken Link
- https://github.com/ArtifexSoftware/ghostpdl-downloads/releases/tag/gs9530Release Notes
FAQ
What is CVE-2020-36773?
CVE-2020-36773 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one U...
How severe is CVE-2020-36773?
CVE-2020-36773 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-36773?
Check the references section above for vendor advisories and patch information. Affected products include: Artifex Ghostscript.