CVE-2021-45944: Use After Free
Published Dec 31, 2021
·Updated
Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampleddatasample (called from sampleddatacontinue and interp).
Affected Software
5 affected componentsFixes available
debian/ghostscript
9.27~dfsg-2+deb10u59.27~dfsg-2+deb10u99.53.3~dfsg-7+deb11u69.53.3~dfsg-7+deb11u510.0.0~dfsg-11+deb12u210.0.0~dfsg-11+deb12u110.02.0~dfsg-2
Artifex Ghostscript>=9.50<=9.53.3
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Event History
Dec 31, 2021
CVE Published
via MITRE·11:56 PM
Data Sourced
via MITRE·11:56 PM
Description
Jan 1, 2022
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-45944?
CVE-2021-45944 is a vulnerability in Ghostscript GhostPDL versions 9.50 through 9.53.3 that allows for a use-after-free in the sampled_data_sample function.
2
How severe is CVE-2021-45944?
CVE-2021-45944 has a severity rating of medium (5.5).
3
How can I fix CVE-2021-45944?
To fix CVE-2021-45944, upgrade to a patched version of Ghostscript GhostPDL, such as version 9.53.4 or later.
4
What is the affected software for CVE-2021-45944?
The affected software for CVE-2021-45944 includes Ghostscript GhostPDL versions 9.50 through 9.53.3.
5
Where can I find more information about CVE-2021-45944?
You can find more information about CVE-2021-45944 in the references provided: [LINK]