Input validation error in Ghostscript - CVE-2025-27837

 

Input validation error in Ghostscript - CVE-2025-27837

Published: March 31, 2025


Vulnerability identifier: #VU106279
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-27837
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of file path with invalid UTF-8 characters in base/gp_mswin.c and base/winrtsup.cpp. A remote attacker can trick the victim to open a specially crafted file and access arbitrary files on the system.


Affected software

Ghostscript
Gentoo Linux
Anolis OS
Fedora
ghostscript
ghostscript-gtk
ghostscript-tools-dvipdf
ghostscript-tools-fonts
ghostscript-tools-printing
ghostscript-x11
libgs
libgs-devel
ghostscript-doc
app-text/ghostscript-gpl

How to mitigate CVE-2025-27837

Install updates from vendor's website.

Ghostscript - update to 10.05.0
ghostscript - addressed in versions 10.02.1-14.fc40, 10.03.1-5.fc41
ghostscript - update to 10.03.0-8
ghostscript-gtk - update to 10.03.0-8
ghostscript-tools-dvipdf - update to 10.03.0-8
ghostscript-tools-fonts - update to 10.03.0-8
ghostscript-tools-printing - update to 10.03.0-8
ghostscript-x11 - update to 10.03.0-8
libgs - update to 10.03.0-8
libgs-devel - update to 10.03.0-8
ghostscript-doc - update to 10.03.0-8
app-text/ghostscript-gpl - update to 10.05.1

External References

Related Security Bulletins