Logo
componentghostscript
Name
ghostscript
Version
10.05.1
Type
library
Description
The GPL Ghostscript PostScript/PDF interpreter
Licenses
AGPL-3.0-or-later
PURL
-
CPE
cpe:2.3:*:artifex:ghostscript:10.05.1:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
9.55.0
master
10.07.1

Patches#


#
Title
Author
Resolve
1
avoid host contamination
Kai Kang <kai.kang@windriver.com>
2
pdfwrite - avoid buffer overrun
Ken Sharp <Ken.Sharp@artifex.com>
CVE-2025-59798
3
pdfwrite - bounds check some strings
Piotr Kajda <petermasterperfect@gmail.com>
CVE-2025-59799
4
base/gendev.c: fix for -Werror=return-type
Robert Yang <liezhi.yang@windriver.com>
5
PDF OCR 8 bit device - avoid overflow
Ken Sharp <Ken.Sharp@artifex.com>
CVE-2025-59800
6
Bug 708160: Fix compatibility with C23 compilers
Alex Cherepanov <alex@coscript.biz>

Vulnerabilities#


Name
Analysis
Description
Patched
In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.
Patched
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdfmark_coerce_dest in devices/vector/gdevpdfm.c via a large size value.
Patched
Artifex Ghostscript through 10.05.1 has a stack-based buffer overflow in pdf_write_cmap in devices/vector/gdevpdtw.c.
False Positive
An integer overflow flaw was found in pcl/pl/plfont.c:418 in pl_glyph_name in ghostscript. This issue may allow a local attacker to cause a denial of service via transforming a crafted PCL file to PDF format.
False Positive
A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.