
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59798 is a stack-based buffer overflow vulnerability in Artifex Ghostscript affecting all versions through 10.05.1. The flaw resides in the pdf_write_cmap function within devices/vector/gdevpdtw.c, which handles PDF CMap (character mapping) writing operations. It was published on September 22, 2025, with a patch commit made available on September 25, 2025. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) per NVD, with availability impact rated High and no confidentiality or integrity impact (Red Hat Advisory, Ghostscript Commit).
The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow), occurring in the pdf_write_cmap function in devices/vector/gdevpdtw.c within Ghostscript's PDF vector device subsystem. An attacker with local access can supply a crafted input (e.g., a malicious PDF or PostScript file) that triggers the overflow during CMap processing, potentially corrupting stack memory. The attack vector is local, requires low privileges, no user interaction, and has low attack complexity. A bug report and the fixing commit are publicly available (Ghostscript Bug Tracker, Ghostscript Commit).
Successful exploitation of this vulnerability primarily impacts availability, as the stack-based buffer overflow can cause Ghostscript to crash or become unresponsive, resulting in a denial-of-service condition. There is no assessed confidentiality impact, and integrity impact is considered minimal. Systems or services that rely on Ghostscript for automated document processing (e.g., print servers, document conversion pipelines) could be disrupted if an attacker can supply malicious input files (Red Hat Advisory).
There is no public proof-of-concept exploit code known at this time, and no evidence of in-the-wild exploitation has been reported. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term (Red Hat Advisory).
Users should upgrade Ghostscript to a version beyond 10.05.1, as the patch was committed on September 25, 2025. Major Linux distributions including Ubuntu (USN-7782-1), Debian (DLA-4330-1, DSA-6024-1), SUSE (SUSE-SU-2025:4125-1, SUSE-SU-2025:4148-1), Amazon Linux 2 (ALAS2-2025-3018), and Fedora have released updated packages. Until patching is possible, administrators should restrict local access to systems running Ghostscript and avoid processing untrusted PDF or PostScript files (Ubuntu Advisory, Amazon Linux Advisory, Ghostscript Commit).
The vulnerability received routine coverage from Linux distribution security teams, with advisories issued by Ubuntu, Debian, SUSE, Amazon Linux, and Fedora. No notable researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking and distribution patching activity (Ubuntu Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."