Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade libgsUpgrade libgs-develUpgrade ghostscript-debuginfoUpgrade ghostscriptUpgrade ghostscript-docUpgrade ghostscript-gtkUpgrade ghostscript-cups | Mar 22, 2023 | Apr 25, 2022 |
| Debian | — | Upgrade ghostscript | May 3, 2022 | Apr 25, 2022 |
| Ghostscript | — | Upgrade to Ghostscript version 9.27 | Jun 1, 2022 | Apr 25, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Aug 18, 2022 | Apr 25, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade ghostscriptUpgrade libgs | Aug 18, 2022 | Apr 25, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 25, 2022 |
| Ubuntu | — | Upgrade ghostscriptUpgrade libgs9Upgrade ghostscript (Ubuntu Pro)Upgrade libgs9 (Ubuntu Pro) | Apr 29, 2022 | Apr 25, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub