---
id: CVE-2021-45949
title: >-
  Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in
  sampled_data_finish (called from sampled_data_continue and interp).
summary: >-
  Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in
  sampled_data_finish (called from sampled_data_continue and interp).
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-787
  - CWE-122
vendor: artifex
product: ghostscript
affected:
  - 'ghostscript >= 9.50, <= 9.54.0'
  - debian_linux = 9.0
  - debian_linux = 10.0
  - debian_linux = 11.0
published: '2022-01-01'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T01:16:31.493'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-45949'
references:
  - url: 'https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=34675'
    label: cve@mitre.org
  - url: >-
      https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=2a3129365d3bc0d4a41f107ef175920d1505d1f7
    label: cve@mitre.org
  - url: >-
      https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-803.yaml
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2022/01/msg00006.html'
    label: cve@mitre.org
  - url: 'https://www.debian.org/security/2022/dsa-5038'
    label: cve@mitre.org
  - url: 'https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=34675'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=2a3129365d3bc0d4a41f107ef175920d1505d1f7
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://github.com/google/oss-fuzz-vulns/blob/main/vulns/ghostscript/OSV-2021-803.yaml
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2022/01/msg00006.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2022/dsa-5038'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-13T15:10:42.414946Z'
scores:
  nvd: 5.5
  adp: 3.9
epss: 0.01401
epssPercentile: 0.71677
ingestedAt: '2026-10-08T01:01:40.727Z'
---

## Overview

Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_data_continue and interp).

## Affected

- `ghostscript >= 9.50, <= 9.54.0`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `debian_linux = 11.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
