CVE-2025-27831Classic Buffer Overflow in Ghostscript

Severity
9.8CRITICALNVD
EPSS
0.3%
top 51.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 25
Latest updateMar 27

Description

An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doc_common.c.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDartifex/ghostscript< 10.05.0
Debianartifex/ghostscript< 9.53.3~dfsg-7+deb11u10+3

Patches

🔴Vulnerability Details

4
OSV
ghostscript vulnerabilities2025-03-27
OSV
CVE-2025-27831: An issue was discovered in Artifex Ghostscript before 102025-03-25
GHSA
GHSA-x74r-f89v-3jw9: An issue was discovered in Artifex Ghostscript before 102025-03-25
CVEList
CVE-2025-27831: An issue was discovered in Artifex Ghostscript before 102025-03-25

📋Vendor Advisories

3
Ubuntu
Ghostscript vulnerabilities2025-03-27
Red Hat
Ghostscript: Text buffer overflow with long characters2025-03-25
Debian
CVE-2025-27831: ghostscript - An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXT...2025