Stack-based buffer overflow in Ghostscript - CVE-2025-59799

 

Stack-based buffer overflow in Ghostscript - CVE-2025-59799

Published: November 17, 2025


Vulnerability identifier: #VU118561
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-59799
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the pdfmark_coerce_dest() function in devices/vector/gdevpdfm.c. A remote attacker can trick the victim into opening a specially crafted file to trigger a stack-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Ghostscript
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Debian Linux
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Anolis OS
ghostscript (Ubuntu package)
ghostscript-debugsource
ghostscript-debuginfo
ghostscript-x11
ghostscript-devel
ghostscript-x11-debuginfo
ghostscript
ghostscript-help
ghostscript-tools-dvipdf
ghostscript (Debian package)
ghostscript-doc
libgs-devel
libgs
ghostscript-tools-printing
ghostscript-tools-fonts
ghostscript-gtk

How to mitigate CVE-2025-59799

Install update from vendor's website.

ghostscript (Ubuntu package) - addressed in versions 9.26~dfsg+0-0ubuntu0.16.04.14+esm10, 9.26~dfsg+0-0ubuntu0.18.04.18+esm5, 9.50~dfsg-5ubuntu4.15+esm2, 9.55.0~dfsg1-0ubuntu5.13, 10.02.1~dfsg1-0ubuntu7.8, 10.05.0dfsg1-0ubuntu1.2
ghostscript-debugsource - addressed in versions 9.52-23.97.1, 9.52-150000.211.1
ghostscript-debuginfo - addressed in versions 9.52-23.97.1, 9.52-150000.211.1
ghostscript-x11 - addressed in versions 9.52-23.97.1, 9.52-150000.211.1
ghostscript-devel - addressed in versions 9.52-23.97.1, 9.52-150000.211.1
ghostscript-x11-debuginfo - addressed in versions 9.52-23.97.1, 9.52-150000.211.1
ghostscript - addressed in versions 9.52-23.97.1, 9.52-150000.211.1
ghostscript-debuginfo - addressed in versions 9.52-25, 9.55.0-22, 9.56.1-18
ghostscript - addressed in versions 9.52-25, 9.55.0-22, 9.56.1-18
ghostscript-help - addressed in versions 9.52-25, 9.55.0-22, 9.56.1-18
ghostscript-tools-dvipdf - addressed in versions 9.52-25, 9.55.0-22, 9.56.1-18
ghostscript-devel - addressed in versions 9.52-25, 9.55.0-22, 9.56.1-18
ghostscript-debugsource - addressed in versions 9.52-25, 9.55.0-22, 9.56.1-18
ghostscript (Debian package) - addressed in versions 10.0.0~dfsg-11+deb12u8, 10.05.1~dfsg-1+deb13u1
ghostscript - update to 10.05.1-2
ghostscript-doc - update to 10.05.1-2
libgs-devel - update to 10.05.1-2
libgs - update to 10.05.1-2
ghostscript-x11 - update to 10.05.1-2
ghostscript-tools-printing - update to 10.05.1-2
ghostscript-tools-fonts - update to 10.05.1-2
ghostscript-tools-dvipdf - update to 10.05.1-2
ghostscript-gtk - update to 10.05.1-2

External References

Related Security Bulletins