First published: Fri Dec 31 2021(Updated: )
Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/ghostscript | 9.27~dfsg-2+deb10u5 9.27~dfsg-2+deb10u9 9.53.3~dfsg-7+deb11u6 9.53.3~dfsg-7+deb11u5 10.0.0~dfsg-11+deb12u2 10.0.0~dfsg-11+deb12u1 10.02.0~dfsg-2 | |
Artifex Software Ghostscript | >=9.50<=9.54.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 |
https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=2a3129365d3bc0d4a41f107ef175920d1505d1f7
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45949 is a vulnerability in Ghostscript GhostPDL versions 9.50 through 9.54.0 that allows a heap-based buffer overflow.
CVE-2021-45949 has a severity rating of 5.5, which is considered medium.
Ghostscript GhostPDL versions 9.50 through 9.54.0 are affected by CVE-2021-45949.
To fix CVE-2021-45949, you should update your Ghostscript GhostPDL installation to a version that includes the fix.
You can find more information about CVE-2021-45949 at the following references: [Reference 1](https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=34675), [Reference 2](https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=2a3129365d3bc0d4a41f107ef175920d1505d1f7), [Reference 3](https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-803.yaml)