Critical severity9.8NVD Advisory· Published Feb 4, 2024· Updated Jun 17, 2026
CVE-2020-36773
CVE-2020-36773
Description
Artifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single character code in a PDF document can map to more than one Unicode code point (e.g., for a ligature).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:a:artifex:ghostscript:9.51:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:artifex:ghostscript:9.51:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:ghostscript:9.52.1:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:ghostscript:9.52:*:*:*:*:*:*:*
- cpe:2.3:a:artifex:ghostscript:9.53.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:artifex:ghostscript:9.53.0:rc2:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: <9.53.0
- osv-coords5 versionspkg:rpm/opensuse/ghostscript&distro=openSUSE%20Leap%2015.5pkg:rpm/suse/ghostscript&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/ghostscript&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/ghostscript&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/ghostscript&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 9.52-150000.185.1+ 4 more
- (no CPE)range: < 9.52-150000.185.1
- (no CPE)range: < 9.52-150000.185.1
- (no CPE)range: < 9.52-23.71.1
- (no CPE)range: < 9.52-23.71.1
- (no CPE)range: < 9.52-23.71.1
Patches
Vulnerability mechanics
References
4- bugs.ghostscript.com/show_bug.cginvdIssue TrackingPatch
- bugzilla.opensuse.org/show_bug.cginvdIssue Tracking
- git.ghostscript.comnvdBroken Link
- github.com/ArtifexSoftware/ghostpdl-downloads/releases/tag/gs9530nvdRelease Notes
News mentions
0No linked articles in our index yet.