Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
2024-02-04T18:16:00.713
2025-05-22T18:15:23.437
Modified
CVSSv3.1: 9.8 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | artifex | ghostscript | 9.51 | Yes |
Application | artifex | ghostscript | 9.52 | Yes |
Application | artifex | ghostscript | 9.52.1 | Yes |
Application | artifex | ghostscript | 9.53.0 | Yes |
Application | artifex | ghostscript | 9.53.0 | Yes |