Out-of-bounds write in Ghostscript - CVE-2020-36773
Published: July 8, 2024
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input in devices/vector/gdevtxtw.c. A remote attacker can create a specially crafted file, trick the victim into opening it using the affected software, trigger an out-of-bounds write and execute arbitrary code on the target system.
Affected software
openEuler
ghostscript
ghostscript-debugsource
ghostscript-tools-dvipdf
ghostscript-debuginfo
ghostscript-devel
ghostscript-help
How to mitigate CVE-2020-36773
ghostscript - addressed in versions 9.52-11, 9.52-13
ghostscript-debugsource - addressed in versions 9.52-11, 9.52-13
ghostscript-tools-dvipdf - addressed in versions 9.52-11, 9.52-13
ghostscript-debuginfo - addressed in versions 9.52-11, 9.52-13
ghostscript-devel - addressed in versions 9.52-11, 9.52-13
ghostscript-help - addressed in versions 9.52-11, 9.52-13