yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2025-59800
Component Overview
Vulnerability Overview
Name
CVE-2025-59800
Source
NVD (
link
)
Debian (
link
)
Description
In Artifex Ghostscript through 10.05.1, ocr_begin_page in devices/gdevpdfocr.c has an integer overflow that leads to a heap-based buffer overflow in ocr_line8.
CWEs
CWE-190
Published Date
Sep 22, 2025
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugs.ghostscript.com/show_bug.cgi?id=708602
Issue Tracking
https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?id=176cf0188a2294bc307b8caec876f39412e58350
Patch
https://bugs.ghostscript.com/show_bug.cgi?id=708602
Issue Tracking
Analysis
#
Affected Component
Analysis
ghostscript
Patched
Vulnerability Ratings
#
4.3
CVSSv31
5.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
ghostscript
buildroot
2025.02.x
10.07.0
Not Affected
ghostscript
buildroot
master
10.07.0
Not Affected
ghostscript
yocto
kirkstone
9.55.0
Patched
ghostscript
yocto
master
10.07.1
Not Affected
Resolved with patches
#
ghostscript (yocto:kirkstone)
#
Title
Author
Resolve
1
PDF OCR 8 bit device - avoid overflow
Ken Sharp <Ken.Sharp@artifex.com>
CVE-2025-59800
ghostscript (yocto:scarthgap)
#
Title
Author
Resolve
1
PDF OCR 8 bit device - avoid overflow
Ken Sharp <Ken.Sharp@artifex.com>
CVE-2025-59800