CVE-2025-59798
published 2025-09-22CVE-2025-59798: Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.
PriorityP428medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.6th percentile
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | <= 10.05.1 | — |
| artifex | ghostscript | >= 0 < 9.53.3~dfsg-7+deb11u11 | 9.53.3~dfsg-7+deb11u11 |
| artifex | ghostscript | >= 0 < 10.0.0~dfsg-11+deb12u8 | 10.0.0~dfsg-11+deb12u8 |
| artifex | ghostscript | >= 0 < 10.05.1~dfsg-1+deb13u1 | 10.05.1~dfsg-1+deb13u1 |
| artifex | ghostscript | >= 0 < 10.06.0~dfsg-1 | 10.06.0~dfsg-1 |
| artifex | ghostscript | >= 0 < 9.55.0~dfsg1-0ubuntu5.13 | 9.55.0~dfsg1-0ubuntu5.13 |
| artifex | ghostscript | >= 0 < 10.02.1~dfsg1-0ubuntu7.8 | 10.02.1~dfsg1-0ubuntu7.8 |
| debian | ghostscript | < ghostscript 10.0.0~dfsg-11+deb12u8 (bookworm) | ghostscript 10.0.0~dfsg-11+deb12u8 (bookworm) |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2025-12-03
CVE-2025-59799 Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Ghostscript could be made to crash if it wrote certain files.
Piotr Kajda discovered that Ghostscript incorrectly handled writing certain
files. An attacker could possibly use this issue to cause Ghostscript to
crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2025-09-29·CVSS 4.3
CVE-2025-59799 [MEDIUM] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Several security issues were fixed in Ghostscript.
It was discovered that Ghostscript incorrectly handled opening a file to
write. An attacker could possibly use this issue to cause Ghostscript to
crash, resulting in a denial of service (CVE-2025-7462)
It was discovered that Ghostscript incorrectly handled writing certain
files. An attacker could possibly use this issue to cause Ghostscript to
crash, resulting in a denial of service (CVE-2025-59798, CVE-2025-59799)
It was discovered that Ghostscript incorrectly handled performing OCR on
certain files. An attacker could use this issue to cause Ghostscript to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2025-59800)
Instructions: In general, a standard syste
Red Hat
Artifex Ghostscript: Artifex Ghostscript: Denial of Service via stack-based buffer overflow in pdf_write_cmap
vendor_redhat·2025-09-22·CVSS 4.3
CVE-2025-59798 [MEDIUM] CWE-121 Artifex Ghostscript: Artifex Ghostscript: Denial of Service via stack-based buffer overflow in pdf_write_cmap
Artifex Ghostscript: Artifex Ghostscript: Denial of Service via stack-based buffer overflow in pdf_write_cmap
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.
A flaw was found in Artifex Ghostscript. This vulnerability, a stack-based buffer overflow, exists within the pdf_write_cmap function. An attacker could exploit this by providing malicious input, potentially leading to a denial of service (DoS) where the application becomes unresponsive.
Statement: This vulnerability is rated Moderate for Red Hat products. A stack-based buffer overflow in Artifex Ghostscript's `pdf_write_cmap` function can lead to a denial of service. Exploitation requires processing a specially crafted PDF file, causing the application to become
Debian
CVE-2025-59798: ghostscript - Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_wri...
vendor_debian·2025·CVSS 4.3
CVE-2025-59798 [MEDIUM] CVE-2025-59798: ghostscript - Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_wri...
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.
Scope: local
bookworm: resolved (fixed in 10.0.0~dfsg-11+deb12u8)
bullseye: resolved (fixed in 9.53.3~dfsg-7+deb11u11)
forky: resolved (fixed in 10.06.0~dfsg-1)
sid: resolved (fixed in 10.06.0~dfsg-1)
trixie: resolved (fixed in 10.05.1~dfsg-1+deb13u1)
OSV
ghostscript vulnerabilities
osv·2025-09-29·CVSS 5.5
CVE-2025-7462 [MEDIUM] ghostscript vulnerabilities
ghostscript vulnerabilities
It was discovered that Ghostscript incorrectly handled opening a file to
write. An attacker could possibly use this issue to cause Ghostscript to
crash, resulting in a denial of service (CVE-2025-7462)
It was discovered that Ghostscript incorrectly handled writing certain
files. An attacker could possibly use this issue to cause Ghostscript to
crash, resulting in a denial of service (CVE-2025-59798, CVE-2025-59799)
It was discovered that Ghostscript incorrectly handled performing OCR on
certain files. An attacker could use this issue to cause Ghostscript to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2025-59800)
OSV
CVE-2025-59798: Artifex Ghostscript through 10
osv·2025-09-22·CVSS 5.5
CVE-2025-59798 [MEDIUM] CVE-2025-59798: Artifex Ghostscript through 10
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.
GHSA
GHSA-6q6w-ff4v-hgr5: Artifex Ghostscript through 10
ghsa_unreviewed·2025-09-22
CVE-2025-59798 [MEDIUM] CWE-121 GHSA-6q6w-ff4v-hgr5: Artifex Ghostscript through 10
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-09-22
Published