Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature). CREATE(Triage):(User=admin) CVE-2020-36773 (https://nvd.nist.gov/vuln/detail/CVE-2020-36773)