CVE-2021-45949: Buffer Overflow
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampleddatafinish (called from sampleddatacontinue and interp).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-45949?
CVE-2021-45949 is a vulnerability in Ghostscript GhostPDL versions 9.50 through 9.54.0 that allows a heap-based buffer overflow.
How severe is CVE-2021-45949?
CVE-2021-45949 has a severity rating of 5.5, which is considered medium.
Which software versions are affected by CVE-2021-45949?
Ghostscript GhostPDL versions 9.50 through 9.54.0 are affected by CVE-2021-45949.
How can I fix CVE-2021-45949?
To fix CVE-2021-45949, you should update your Ghostscript GhostPDL installation to a version that includes the fix.
Where can I find more information about CVE-2021-45949?
You can find more information about CVE-2021-45949 at the following references: [Reference 1](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=34675), [Reference 2](https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=2a3129365d3bc0d4a41f107ef175920d1505d1f7), [Reference 3](https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-803.yaml)