#VU106279 Input validation error in Ghostscript - CVE-2025-27837
Published: March 31, 2025
Ghostscript
Artifex Software, Inc.
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of file path with invalid UTF-8 characters in base/gp_mswin.c and base/winrtsup.cpp. A remote attacker can trick the victim to open a specially crafted file and access arbitrary files on the system.