yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2025-48708
Component Overview
Vulnerability Overview
Name
CVE-2025-48708
Source
NVD (
link
)
Debian (
link
)
Description
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.
CWEs
CWE-212
Published Date
May 23, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugs.ghostscript.com/show_bug.cgi?id=708446
Issue Tracking
https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=b587663c623b4462f9e78686a31fd880207303ee
Patch
http://www.openwall.com/lists/oss-security/2025/05/23/2
Mailing List
Analysis
#
Affected Component
Analysis
ghostscript
Patched
Vulnerability Ratings
#
4
CVSSv31
3.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
ghostscript
buildroot
2025.02.x
10.07.0
Not Affected
ghostscript
buildroot
master
10.07.0
Not Affected
ghostscript
yocto
master
10.07.1
Not Affected
ghostscript
yocto
scarthgap
10.05.1
Not Affected
Resolved with patches
#
ghostscript (yocto:kirkstone)
#
Title
Author
Resolve
1
Argument sanitisation - handle '#' as per '='
Ken Sharp <Ken.Sharp@artifex.com>
CVE-2025-48708