In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ghostscript | Dec 5, 2025 | Sep 22, 2025 |
| Amazon Linux Ami 2 | — | Upgrade libgsUpgrade libgs-develUpgrade ghostscript-debuginfoUpgrade ghostscriptUpgrade ghostscript-cupsUpgrade ghostscript-gtkUpgrade ghostscript-doc | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade ghostscript-x11Upgrade libgsUpgrade ghostscriptUpgrade libgs-develUpgrade ghostscript-tools-dvipdfUpgrade ghostscript-gtk-debuginfoUpgrade ghostscript-debugsourceUpgrade ghostscript-debuginfoUpgrade ghostscript-tools-fontsUpgrade ghostscript-x11-debuginfoUpgrade ghostscript-tools-printingUpgrade libgs-debuginfoUpgrade ghostscript-gtkUpgrade ghostscript-doc | Oct 16, 2025 | Sep 22, 2025 |
| Ghostscript | — | Upgrade to Ghostscript version 10.06.0 | Mar 30, 2026 | Sep 22, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Sep 22, 2025 |
| Ubuntu | — | Upgrade libgs10Upgrade libgs9Upgrade ghostscript | Sep 30, 2025 | Sep 22, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub