Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 22 May 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-22T17:29:16.336Z
Reserved: 2024-02-04T00:00:00.000Z
Link: CVE-2020-36773
Updated: 2024-08-04T17:37:07.276Z
Status : Modified
Published: 2024-02-04T18:16:00.713
Modified: 2025-05-22T18:15:23.437
Link: CVE-2020-36773
OpenCVE Enrichment
No data.