CVE-2025-59800
Ghostscript vulnerability analysis and mitigation

Overview

CVE-2025-59800 affects Artifex Ghostscript through version 10.05.1. The vulnerability stems from an integer overflow in the ocrbeginpage function within devices/gdevpdfocr.c, which leads to a heap-based buffer overflow in ocrline8. The issue was discovered on June 13, 2025, and was publicly disclosed with a fix on July 1, 2025 ([Ghostscript Bug](https://bugs.ghostscript.com/showbug.cgi?id=708602)).

Technical details

The vulnerability occurs due to an integer overflow during memory allocation in the ocrbeginpage function located in devices/gdevpdfocr.c line 526. This overflow subsequently leads to a heap-based buffer overflow in the ocr_line8 function at line 461. The CVSS 3.1 score is 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

When exploited, this vulnerability can cause Ghostscript to crash, resulting in a denial of service. Under certain conditions, there is also the potential for arbitrary code execution (Ubuntu Notice).

Mitigation and workarounds

A fix has been implemented in commit 176cf0188a2294bc307b8caec876f39412e58350, which adds a range check before memory allocation. Users should upgrade to the patched versions available through their distribution channels. Ubuntu has released fixes in versions 10.05.0dfsg1-0ubuntu1.2 for Ubuntu 25.04, 10.02.1~dfsg1-0ubuntu7.8 for Ubuntu 24.04 LTS, and 9.55.0~dfsg1-0ubuntu5.13 for Ubuntu 22.04 LTS (Ubuntu Notice).

Additional resources


SourceThis report was generated using AI

Related Ghostscript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-59800MEDIUM5.5
  • GhostscriptGhostscript
  • ghostscript-debugsource
NoYesSep 22, 2025
CVE-2025-59799MEDIUM5.5
  • GhostscriptGhostscript
  • ghostscript-x11-debuginfo
NoYesSep 22, 2025
CVE-2025-59798MEDIUM5.5
  • GhostscriptGhostscript
  • ghostscript
NoYesSep 22, 2025
CVE-2025-7462MEDIUM5.3
  • GhostscriptGhostscript
  • libgs-devel
NoYesJul 12, 2025
CVE-2025-59801MEDIUM4.3
  • GhostscriptGhostscript
  • ghostscript
NoYesSep 22, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management