Description
In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:NExploitability: 1.4 | Impact: 2.7Attack Vector: Local
Complexity: High
Privileges: None
User Interaction: None
Scope: Changed
Confidentiality: Low
Integrity: Low
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
3CVEListCVE-2025-46646: In Artifex Ghostscript before 10↗2025-04-26 ▶ GHSAGHSA-56g6-5g9j-wjc3: In Artifex Ghostscript before 10↗2025-04-26 ▶ OSVCVE-2025-46646: In Artifex Ghostscript before 10↗2025-04-26 ▶ 📋Vendor Advisories
3UbuntuGhostscript vulnerability↗2025-05-01 ▶ Red HatGhostscript: Mishandling of Overlong UTF-8 Encoding in Artifex Ghostscript's decode_utf8 Function↗2025-04-26 ▶ DebianCVE-2025-46646: ghostscript - In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles ...↗2025 ▶