CVE-2020-36773: Use After Free
Published Feb 4, 2024
·Updated
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
Affected Software
5 affected components
Artifex ghostscript=9.51
Artifex ghostscript=9.52
Artifex ghostscript=9.52.1
Artifex ghostscript=9.53.0-rc1
Artifex ghostscript=9.53.0-rc2
Remediation
Patch Available
Event History
Feb 4, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-36773?
CVE-2020-36773 is considered a medium severity vulnerability due to the potential for out-of-bounds write and use-after-free conditions.
2
How do I fix CVE-2020-36773?
To mitigate CVE-2020-36773, upgrade to Ghostscript version 9.53.0 or later.
3
What are the affected versions for CVE-2020-36773?
Affected versions for CVE-2020-36773 include Ghostscript versions 9.51, 9.52, and 9.52.1.
4
What type of vulnerability is CVE-2020-36773?
CVE-2020-36773 is classified as an out-of-bounds write and use-after-free vulnerability.
5
Which software is impacted by CVE-2020-36773?
CVE-2020-36773 impacts Artifex Ghostscript software versions prior to 9.53.0.