Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-59798

Опубликовано: 22 сент. 2025
Источник: redhat
CVSS3: 4
EPSS Низкий

Описание

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.

A flaw was found in Artifex Ghostscript. This vulnerability, a stack-based buffer overflow, exists within the pdf_write_cmap function. An attacker could exploit this by providing malicious input, potentially leading to a denial of service (DoS) where the application becomes unresponsive.

Отчет

This vulnerability is rated Moderate for Red Hat products. A stack-based buffer overflow in Artifex Ghostscript's pdf_write_cmap function can lead to a denial of service. Exploitation requires processing a specially crafted PDF file, causing the application to become unresponsive.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10ghostscriptFix deferred
Red Hat Enterprise Linux 6ghostscriptFix deferred
Red Hat Enterprise Linux 7ghostscriptFix deferred
Red Hat Enterprise Linux 8ghostscriptFix deferred
Red Hat Enterprise Linux 9ghostscriptFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-121
https://bugzilla.redhat.com/show_bug.cgi?id=2397225Artifex Ghostscript: Artifex Ghostscript: Denial of Service via stack-based buffer overflow in pdf_write_cmap

EPSS

Процентиль: 9%
0.00188
Низкий

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
11 месяцев назад

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.

CVSS3: 4.3
nvd
11 месяцев назад

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.

CVSS3: 4.3
debian
11 месяцев назад

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow ...

CVSS3: 4.3
github
11 месяцев назад

Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.

CVSS3: 4.3
fstec
больше 1 года назад

Уязвимость функции pdf_write_cmap набора программного обеспечения для обработки, преобразования и генерации документов Ghostscript, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 9%
0.00188
Низкий

4 Medium

CVSS3