gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ghostscriptUpgrade ghostscript-docUpgrade libgs-develUpgrade libgsUpgrade ghostscript-gtkUpgrade ghostscript-debuginfoUpgrade ghostscript-cups | Jun 13, 2025 | May 23, 2025 |
| Amazon_linux_2023 | — | Upgrade libgs-develUpgrade ghostscript-x11Upgrade ghostscript-debugsourceUpgrade ghostscript-debuginfoUpgrade ghostscript-gtkUpgrade ghostscript-tools-fontsUpgrade ghostscript-tools-dvipdfUpgrade libgs-debuginfoUpgrade ghostscript-docUpgrade ghostscriptUpgrade ghostscript-gtk-debuginfoUpgrade libgsUpgrade ghostscript-tools-printingUpgrade ghostscript-x11-debuginfo | Jun 11, 2025 | May 23, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 23, 2025 |
| Debian | — | No solution existsUpgrade ghostscript | May 28, 2025 | May 23, 2025 |
| Ghostscript | — | Upgrade to Ghostscript version 10.05.1 | Feb 11, 2026 | May 23, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade ghostscript-helpUpgrade ghostscript | Sep 15, 2025 | Sep 9, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 23, 2025 |
| Suse | — | Upgrade ghostscript-develUpgrade ghostscript-x11Upgrade ghostscript | Dec 5, 2025 | Oct 7, 2025 |
| Ubuntu | — | Upgrade ghostscriptUpgrade libgs9-common (Ubuntu Pro)Upgrade libgs9Upgrade ghostscript-xUpgrade libgs9 (Ubuntu Pro)Upgrade ghostscript-x (Ubuntu Pro)Upgrade libgs10Upgrade ghostscript (Ubuntu Pro)Upgrade libgs-dev (Ubuntu Pro) | Jul 9, 2025 | May 23, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub