// For flags

CVE-2020-36773

 

Severity Score

9.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

Artifex Ghostscript anterior a 9.53.0 tiene una escritura y un use-after-free fuera de los límites en devices/vector/gdevtxtw.c (para txtwrite) porque un código de un solo carácter en un documento PDF se puede asignar a más de un punto de código Unicode. (por ejemplo, para una ligadura).

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2024-02-04 CVE Reserved
  • 2024-02-04 CVE Published
  • 2024-02-13 EPSS Updated
  • 2024-08-04 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-416: Use After Free
  • CWE-787: Out-of-bounds Write
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Artifex
Search vendor "Artifex"
Ghostscript
Search vendor "Artifex" for product "Ghostscript"
9.51
Search vendor "Artifex" for product "Ghostscript" and version "9.51"
-
Affected
Artifex
Search vendor "Artifex"
Ghostscript
Search vendor "Artifex" for product "Ghostscript"
9.52
Search vendor "Artifex" for product "Ghostscript" and version "9.52"
-
Affected
Artifex
Search vendor "Artifex"
Ghostscript
Search vendor "Artifex" for product "Ghostscript"
9.52.1
Search vendor "Artifex" for product "Ghostscript" and version "9.52.1"
-
Affected
Artifex
Search vendor "Artifex"
Ghostscript
Search vendor "Artifex" for product "Ghostscript"
9.53.0
Search vendor "Artifex" for product "Ghostscript" and version "9.53.0"
rc1
Affected
Artifex
Search vendor "Artifex"
Ghostscript
Search vendor "Artifex" for product "Ghostscript"
9.53.0
Search vendor "Artifex" for product "Ghostscript" and version "9.53.0"
rc2
Affected