PT-2025-22637 · Artifex+5 · Artifex Ghostscript+5
Published
2025-04-11
·
Updated
2026-04-21
·
CVE-2025-48708
CVSS v3.1
4.0
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Artifex Ghostscript versions prior to 10.05.1
Description
The issue lacks argument sanitization for the # case in the
gs lib ctx stash sanitized arg function in base/gslibctx.c. This allows a created PDF document to include its password in cleartext.Recommendations
For versions prior to 10.05.1, update to version 10.05.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
gs lib ctx stash sanitized arg function in base/gslibctx.c until a patch is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Artifex Ghostscript
Debian
Linuxmint
Suse
Ubuntu