Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue and interp).
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ghostscript | Mar 21, 2024 | Dec 31, 2021 |
| Debian | — | Upgrade ghostscript | Jan 10, 2022 | Jan 1, 2022 |
| Ghostscript | — | Upgrade to Ghostscript version 9.54 | Feb 24, 2022 | Dec 31, 2021 |
| Huawei Euleros 2_0_sp10 | — | Upgrade ghostscript-helpUpgrade ghostscript | Apr 20, 2022 | Jan 1, 2022 |
| Huawei Euleros 2_0_sp3 | — | Upgrade ghostscriptUpgrade ghostscript-cups | May 25, 2022 | Jan 1, 2022 |
| Huawei Euleros 2_0_sp5 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Apr 26, 2022 | Jan 1, 2022 |
| Huawei Euleros 2_0_sp9 | — | Upgrade ghostscriptUpgrade ghostscript-help | Apr 19, 2022 | Jan 1, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 1, 2022 |
| Suse | — | Upgrade ghostscriptUpgrade ghostscript-develUpgrade ghostscript-x11 | Jan 15, 2022 | Jan 1, 2022 |
| Ubuntu | — | Upgrade ghostscriptUpgrade libgs9Upgrade libgs9 (Ubuntu Pro)Upgrade ghostscript (Ubuntu Pro) | Jan 13, 2022 | Jan 1, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub