Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ghostscript-debuginfoUpgrade ghostscript-docUpgrade ghostscriptUpgrade libgsUpgrade libgs-develUpgrade ghostscript-cupsUpgrade ghostscript-gtk | Mar 22, 2023 | Apr 25, 2022 |
| Debian | — | Upgrade ghostscript | May 3, 2022 | Apr 25, 2022 |
| Ghostscript | — | Upgrade to Ghostscript version 9.27 | Jun 1, 2022 | Apr 25, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Aug 18, 2022 | Apr 25, 2022 |
| Huawei Euleros 2_0_sp8 | — | Upgrade ghostscriptUpgrade libgs | Aug 18, 2022 | Apr 25, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 25, 2022 |
| Ubuntu | — | Upgrade ghostscript (Ubuntu Pro)Upgrade ghostscriptUpgrade libgs9Upgrade libgs9 (Ubuntu Pro) | Apr 29, 2022 | Apr 25, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub