PT-2019-6413 · Artifex+3 · Artifex Ghostscript+3

Suhwan

·

Published

2019-11-05

·

Updated

2023-09-25

·

CVE-2020-21890

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Artifex Ghostscript version 9.50
Description The issue is related to a Buffer Overflow vulnerability in the clj media size function in the devices/gdevclj.c component. This vulnerability can be exploited by remote attackers via the opening of a crafted PDF document, potentially leading to a denial of service or other unspecified impacts. It may also allow attackers to access confidential data, compromise data integrity, and cause service disruption.
Recommendations For Artifex Ghostscript version 9.50, consider disabling the clj media size function as a temporary workaround until a patch is available. Restrict access to crafted PDF documents to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2023-09075
CVE-2020-21890
DLA-3582-1
USN-6364-1

Affected Products

Artifex Ghostscript
Astra Linux
Linuxmint
Ubuntu