gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.
CVSS Details
- CVSS 3.1 Base Score: 4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade ghostscript-gtkUpgrade ghostscript-cupsUpgrade ghostscript-debuginfoUpgrade ghostscript-docUpgrade ghostscriptUpgrade libgs-develUpgrade libgs | Jun 13, 2025 | May 23, 2025 |
| Amazon_linux_2023 | — | Upgrade libgs-debuginfoUpgrade ghostscript-docUpgrade ghostscript-tools-dvipdfUpgrade ghostscript-tools-printingUpgrade ghostscript-x11-debuginfoUpgrade ghostscriptUpgrade ghostscript-gtk-debuginfoUpgrade libgsUpgrade libgs-develUpgrade ghostscript-tools-fontsUpgrade ghostscript-x11Upgrade ghostscript-debuginfoUpgrade ghostscript-gtkUpgrade ghostscript-debugsource | Jun 11, 2025 | May 23, 2025 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | May 23, 2025 |
| Debian | — | Upgrade ghostscriptNo solution exists | May 28, 2025 | May 23, 2025 |
| Ghostscript | — | Upgrade to Ghostscript version 10.05.1 | Feb 11, 2026 | May 23, 2025 |
| Huawei Euleros 2_0_sp10 | — | Upgrade ghostscriptUpgrade ghostscript-help | Sep 15, 2025 | Sep 9, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 23, 2025 |
| Suse | — | Upgrade ghostscript-x11Upgrade ghostscriptUpgrade ghostscript-devel | Dec 5, 2025 | Oct 7, 2025 |
| Ubuntu | — | Upgrade libgs10Upgrade ghostscript (Ubuntu Pro)Upgrade ghostscript-x (Ubuntu Pro)Upgrade libgs-dev (Ubuntu Pro)Upgrade libgs9 (Ubuntu Pro)Upgrade ghostscript-xUpgrade ghostscriptUpgrade libgs9Upgrade libgs9-common (Ubuntu Pro) | Jul 9, 2025 | May 23, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub