Description
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
References (4)
Core 4
Core References
Issue Tracking, Patch
https://bugs.ghostscript.com/show_bug.cgi?id=702229
Issue Tracking
https://bugzilla.opensuse.org/show_bug.cgi?id=1177922
Scores
CVSS v3
9.8
EPSS
0.0011
EPSS Percentile
28.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-416
CWE-787
Status
published
Products (4)
artifex/ghostscript
9.51
artifex/ghostscript
9.52
artifex/ghostscript
9.52.1
artifex/ghostscript
9.53.0 rc1 (2 CPE variants)
Published
Feb 04, 2024
Tracked Since
Feb 18, 2026