PT-2025-38681 · Artifex+1 · Ghostxps+1

Published

2025-09-22

·

Updated

2026-04-21

·

CVE-2025-59801

CVSS v3.1

4.3

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Artifex GhostXPS versions prior to 10.06.0
Description: A stack-based buffer overflow exists in the xps unpredict tiff function within xpstiff.c due to a missing check on the samplesperpixel value.
Recommendations: Update to version 10.06.0 or later.

Fix

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-11523
CVE-2025-59801
OPENSUSE-SU-2025:15707-1
OPENSUSE-SU-2026:20592-1

Affected Products

Debian
Ghostxps