A null pointer vulnerability was found in memgetbitsrectangle() when trying to read from unallocated memory.
Upstream bug:
https://bugs.ghostscript.com/showbug.cgi?id=697676
Upstream patch:
http://git.ghostscript.com/?p=ghostpdl.git;h=309eca4e0a31ea70dcc844812691439312dad091
The memgetbitsrectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.
Last updated 25 August 2025