PT-2025-22637 · Artifex+6 · Artifex Ghostscript+6

CVE-2025-48708

·

Published

2025-04-11

·

Updated

2026-05-24

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Artifex Ghostscript versions prior to 10.05.1
Description The issue lacks argument sanitization for the # case in the gs lib ctx stash sanitized arg function in base/gslibctx.c. This allows a created PDF document to include its password in cleartext.
Recommendations For versions prior to 10.05.1, update to version 10.05.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the gs lib ctx stash sanitized arg function in base/gslibctx.c until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-8484
ALT-PU-2025-9591
BDU:2025-06028
CVE-2025-48708
MGASA-2025-0170
OESA-2025-1580
OPENSUSE-SU-2025:15413-1
OPENSUSE-SU-2026:20592-1
SUSE-SU-2025:03460-1
SUSE-SU-2025:03461-1
SUSE-SU-2025_03460-1
SUSE-SU-2025_03461-1
SUSE-SU-2026:21363-1
USN-7623-1

Affected Products

Alt Linux
Artifex Ghostscript
Debian
Linuxmint
Red Os
Suse
Ubuntu