FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-04-18 11:12:36 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
62642942-590f-11eb-a0dc-8c164582fbacGhostscript -- SAFER Sandbox Breakout

SO-AND-SO reports:

A memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file access controls. The 'rsearch' calculation for the 'post' size resulted in a size that was too large, and could underflow to max uint32_t. This was fixed in commit 5d499272b95a6b890a1397e11d20937de000d31b.


Discovery 2020-07-28
Entry 2021-01-17
ghostscript9-agpl-base
ge 9.50 lt 9.52_8

https://nvd.nist.gov/vuln/detail/CVE-2020-15900