Wind River Support Network

HomeDefectsLIN1021-7186
Fixed

LIN1021-7186 : Security Advisory - ghostscript - CVE-2020-36773

Created: Feb 4, 2024    Updated: Apr 8, 2024
Resolved Date: Apr 5, 2024
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).

CREATE(Triage):(User=admin) CVE-2020-36773 (https://nvd.nist.gov/vuln/detail/CVE-2020-36773)
Live chat
Online