CVE-2025-46646

CWE-247 documents7 sources
Severity
4.5MEDIUM
EPSS
0.1%
top 75.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 26
Latest updateMay 1

Description

In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:NExploitability: 1.4 | Impact: 2.7

Affected Packages3 packages

CVEListV5artifex/ghostscript< 10.05.0
NVDartifex/ghostscript< 10.05.0
Debianghostscript< 10.05.0~dfsg-1+1

Patches

🔴Vulnerability Details

3
CVEList
CVE-2025-46646: In Artifex Ghostscript before 102025-04-26
GHSA
GHSA-56g6-5g9j-wjc3: In Artifex Ghostscript before 102025-04-26
OSV
CVE-2025-46646: In Artifex Ghostscript before 102025-04-26

📋Vendor Advisories

3
Ubuntu
Ghostscript vulnerability2025-05-01
Red Hat
Ghostscript: Mishandling of Overlong UTF-8 Encoding in Artifex Ghostscript's decode_utf8 Function2025-04-26
Debian
CVE-2025-46646: ghostscript - In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles ...2025
CVE-2025-46646 (MEDIUM CVSS 4.5) | In Artifex Ghostscript before 10.05 | cvebase.io