Description
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 2.5 | Impact: 1.4Attack Vector: Local
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: Low
Integrity: None
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
3GHSAGHSA-7q9j-33vm-8375: gs_lib_ctx_stash_sanitized_arg in base/gslibctx↗2025-05-23 ▶ CVEListCVE-2025-48708: gs_lib_ctx_stash_sanitized_arg in base/gslibctx↗2025-05-23 ▶ OSVCVE-2025-48708: gs_lib_ctx_stash_sanitized_arg in base/gslibctx↗2025-05-23 ▶ 📋Vendor Advisories
3UbuntuGhostscript vulnerabilities↗2025-07-08 ▶ Red HatGhostscript: Ghostscript Argument Sanitization Vulnerability↗2025-05-23 ▶ DebianCVE-2025-48708: ghostscript - gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before ...↗2025 ▶