CVE-2025-48708
published 2025-05-23CVE-2025-48708: gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document…
PriorityP412low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.29%
20.9th percentile
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | < 10.05.1 | 10.05.1 |
| artifex | ghostscript | >= 0 < 10.05.1~dfsg-1 | 10.05.1~dfsg-1 |
| artifex | ghostscript | >= 0 < 10.05.1~dfsg-1 | 10.05.1~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.12 | 9.55.0~dfsg1-0ubuntu5.12 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg1-0ubuntu7.7 | 10.02.1~dfsg1-0ubuntu7.7 |
| artifex | ghostscript | >= 0 < 9.26~dfsg+0-0ubuntu0.16.04.14+esm9 | 9.26~dfsg+0-0ubuntu0.16.04.14+esm9 |
| artifex | ghostscript | >= 0 < 9.26~dfsg+0-0ubuntu0.18.04.18+esm4 | 9.26~dfsg+0-0ubuntu0.18.04.18+esm4 |
| artifex | ghostscript | >= 0 < 9.50~dfsg-5ubuntu4.15+esm1 | 9.50~dfsg-5ubuntu4.15+esm1 |
| debian | ghostscript | < ghostscript 10.05.1~dfsg-1 (forky) | ghostscript 10.05.1~dfsg-1 (forky) |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
osv4.3MEDIUM
vendor_ubuntu4.3MEDIUM
vendor_debian4.0LOW
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ghostscript vulnerabilities
osv·2025-07-08·CVSS 4.3
CVE-2023-39327 [MEDIUM] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that OpenJPEG, vendored in Ghostscript did not correctly
handle large image files. If a user or system were tricked into opening a
specially crafted file, an attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2023-39327) Thomas Rinsma discovered that Ghostscript did
not correctly handle printing certain variables. An attacker could possibly
use this issue to leak sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-29508) It was discovered
that Ghostscript did not correctly handle loading certain libraries. An
attacker could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 16.04 LT
GHSA
GHSA-7q9j-33vm-8375: gs_lib_ctx_stash_sanitized_arg in base/gslibctx
ghsa_unreviewed·2025-05-23
CVE-2025-48708 [LOW] CWE-212 GHSA-7q9j-33vm-8375: gs_lib_ctx_stash_sanitized_arg in base/gslibctx
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript through 10.05.0 lacks argument sanitization for the # case.
OSV
CVE-2025-48708: gs_lib_ctx_stash_sanitized_arg in base/gslibctx
osv·2025-05-23·CVSS 3.3
CVE-2025-48708 [LOW] CVE-2025-48708: gs_lib_ctx_stash_sanitized_arg in base/gslibctx
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2025-07-08·CVSS 4.3
CVE-2025-27835 [MEDIUM] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that OpenJPEG, vendored in Ghostscript did not correctly
handle large image files. If a user or system were tricked into opening a
specially crafted file, an attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu
18.04 LTS. (CVE-2023-39327) Thomas Rinsma discovered that Ghostscript did
not correctly handle printing certain variables. An attacker could possibly
use this issue to leak sensitive information. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-29508) It was discovered
that Ghostscript did not correctly handle loading certain libraries. An
attacker could possibly use this issue
Red Hat
Ghostscript: Ghostscript Argument Sanitization Vulnerability
vendor_redhat·2025-05-23·CVSS 4.0
CVE-2025-48708 [MEDIUM] CWE-212 Ghostscript: Ghostscript Argument Sanitization Vulnerability
Ghostscript: Ghostscript Argument Sanitization Vulnerability
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.
A flaw was found in Artifex Ghostscript. This vulnerability may allow arbitrary code execution via a crafted PostScript document.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: ghostscript (Red Hat Enterprise Linux 10) - Fix deferred
Package: ghostscript (Red Hat Enterprise Linux 6) - Fix deferred
Package: ghostscript (Red Hat Enter
Debian
CVE-2025-48708: ghostscript - gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before ...
vendor_debian·2025·CVSS 4.0
CVE-2025-48708 [MEDIUM] CVE-2025-48708: ghostscript - gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before ...
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 10.05.1~dfsg-1)
sid: resolved (fixed in 10.05.1~dfsg-1)
trixie: resolved (fixed in 10.05.1~dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-23
Published