{"id":"CVE-2021-45949","title":"Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).","summary":"Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-787","CWE-122"],"vendor":"artifex","product":"ghostscript","affected":["ghostscript >= 9.50, <= 9.54.0","debian_linux = 9.0","debian_linux = 10.0","debian_linux = 11.0"],"published":"2022-01-01","updated":"2026-10-08","sourceUpdated":"2026-10-08T01:16:31.493","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-45949","references":[{"url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=34675","label":"cve@mitre.org"},{"url":"https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=2a3129365d3bc0d4a41f107ef175920d1505d1f7","label":"cve@mitre.org"},{"url":"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-803.yaml","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2022/01/msg00006.html","label":"cve@mitre.org"},{"url":"https://www.debian.org/security/2022/dsa-5038","label":"cve@mitre.org"},{"url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=34675","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=2a3129365d3bc0d4a41f107ef175920d1505d1f7","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-803.yaml","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2022/01/msg00006.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2022/dsa-5038","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-07-13T15:10:42.414946Z"},"scores":{"nvd":5.5,"adp":3.9},"epss":0.01401,"epssPercentile":0.71677,"ingestedAt":"2026-10-08T01:01:40.727Z","slug":"CVE-2021-45949","body":"## Overview\n\nGhostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).\n\n## Affected\n\n- `ghostscript >= 9.50, <= 9.54.0`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":30.3,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[{"seq":217857,"id":"CVE-2021-45949","ts":1791424983658,"field":"cvss","old":"3.9","new":"5.5"},{"seq":217856,"id":"CVE-2021-45949","ts":1791424983658,"field":"severity","old":"low","new":"medium"}]}