CVE-2019-25059
Ghostscript vulnerability analysis and mitigation

Overview

Artifex Ghostscript through version 9.26 contains a security vulnerability related to the mishandling of .completefont. This vulnerability is particularly notable as it emerged from an incomplete fix for a previous vulnerability (CVE-2019-3839). The issue was disclosed and assigned CVE-2019-25059 on April 25, 2022 (CVE Mitre).

Technical details

The vulnerability stems from the improper handling of privileged PostScript operators that remained accessible from various locations. This security flaw allows specially crafted PostScript files to bypass the constraints imposed by the -dSAFER security feature, potentially gaining unauthorized access to the file system (Debian LTS).

Impact

When exploited, this vulnerability enables attackers to access the file system outside of the security constraints that should be enforced by the -dSAFER option. This poses a significant security risk as it could lead to unauthorized file system access and potential system compromise (Debian LTS).

Mitigation and workarounds

The issue has been addressed in various distributions with security updates. For Debian 9 (stretch), the fix was implemented in version 9.26a~dfsg-0+deb9u9. Other versions have also received patches, including bullseye (9.53.3~dfsg-7+deb11u9) and bookworm (10.0.0~dfsg-11+deb12u6) (Security Tracker).

Additional resources


SourceThis report was generated using AI

Related Ghostscript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-59800MEDIUM5.5
  • GhostscriptGhostscript
  • ghostscript-devel
NoYesSep 22, 2025
CVE-2025-59799MEDIUM5.5
  • GhostscriptGhostscript
  • ghostscript-cups
NoYesSep 22, 2025
CVE-2025-59798MEDIUM5.5
  • GhostscriptGhostscript
  • ghostscript-gtk
NoYesSep 22, 2025
CVE-2025-7462MEDIUM5.3
  • GhostscriptGhostscript
  • ghostscript-tools-fonts
NoYesJul 12, 2025
CVE-2025-59801MEDIUM4.3
  • GhostscriptGhostscript
  • ghostscript
NoYesSep 22, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management