Description
A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Ubuntu USN |
USN-4445-1 | Ghostscript vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T13:30:23.341Z
Reserved: 2020-07-22T00:00:00.000Z
Link: CVE-2020-15900
No data.
Status : Modified
Published: 2020-07-28T16:15:12.840
Modified: 2024-11-21T05:06:24.667
Link: CVE-2020-15900
OpenCVE Enrichment
No data.
Ubuntu USN