PT-2025-22637 · Artifex+5 · Artifex Ghostscript+5

Published

2025-04-11

·

Updated

2026-04-21

·

CVE-2025-48708

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Artifex Ghostscript versions prior to 10.05.1
Description The issue lacks argument sanitization for the # case in the gs lib ctx stash sanitized arg function in base/gslibctx.c. This allows a created PDF document to include its password in cleartext.
Recommendations For versions prior to 10.05.1, update to version 10.05.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the gs lib ctx stash sanitized arg function in base/gslibctx.c until a patch is available.

Fix

Weakness Enumeration

Related Identifiers

ALT-PU-2025-8484
ALT-PU-2025-9591
BDU:2025-06028
CVE-2025-48708
MGASA-2025-0170
OESA-2025-1580
OPENSUSE-SU-2025:15413-1
OPENSUSE-SU-2026:20592-1
SUSE-SU-2025:03460-1
SUSE-SU-2025:03461-1
SUSE-SU-2025_03460-1
SUSE-SU-2025_03461-1
SUSE-SU-2026:21363-1
USN-7623-1

Affected Products

Alt Linux
Artifex Ghostscript
Debian
Linuxmint
Suse
Ubuntu