PT-2019-6413 · Artifex+3 · Artifex Ghostscript+3
Suhwan
·
Published
2019-11-05
·
Updated
2023-09-25
·
CVE-2020-21890
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Artifex Ghostscript version 9.50
Description
The issue is related to a Buffer Overflow vulnerability in the
clj media size function in the devices/gdevclj.c component. This vulnerability can be exploited by remote attackers via the opening of a crafted PDF document, potentially leading to a denial of service or other unspecified impacts. It may also allow attackers to access confidential data, compromise data integrity, and cause service disruption.Recommendations
For Artifex Ghostscript version 9.50, consider disabling the
clj media size function as a temporary workaround until a patch is available. Restrict access to crafted PDF documents to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Artifex Ghostscript
Astra Linux
Linuxmint
Ubuntu