
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59800 is an integer overflow vulnerability in Artifex Ghostscript through version 10.05.1, located in the ocr_begin_page function within devices/gdevpdfocr.c. The overflow leads to a heap-based buffer overflow in the ocr_line8 component. It was published on September 22, 2025, with a patch committed to the Ghostscript repository shortly after. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) with a local attack vector (Red Hat CVE, Ghostscript Commit).
The root cause is an integer overflow (CWE-190) in the ocr_begin_page function in devices/gdevpdfocr.c, which is part of Ghostscript's PDF OCR device handling. When processing certain inputs, the integer overflow causes an undersized heap buffer to be allocated, which is subsequently overflowed during the ocr_line8 operation. Exploitation requires local access with low privileges and no user interaction. The fix was committed to the GhostPDL repository and is referenced in the Ghostscript bug tracker (Ghostscript Bug, Ghostscript Commit).
Successful exploitation of this vulnerability primarily impacts availability, as the heap-based buffer overflow can cause system instability or crashes in Ghostscript processes. Confidentiality is not impacted, and integrity impact is assessed as none under the NVD scoring. The vulnerability is locally scoped, limiting its reach to systems where an attacker already has low-privileged local access, such as shared document processing environments (Red Hat CVE).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins have been released by Nessus and Qualys for scanning purposes (Red Hat CVE, Tenable Nessus).
Users should upgrade Ghostscript to a version beyond 10.05.1, as the patch has been committed to the upstream GhostPDL repository. Until an upgrade is possible, restrict access to Ghostscript processing to trusted local users only and implement strict input validation for documents processed by Ghostscript. Ubuntu has issued security notice USN-7782-1, Amazon Linux has released ALAS2-2025-3018, and Fedora and NixOS packages have also been updated (Ubuntu Advisory, Amazon Linux, Ghostscript Commit).
Red Hat has published a CVE advisory tracking this vulnerability, and multiple Linux distributions including Ubuntu, Amazon Linux, and Fedora have issued security updates. The Yocto Project security mailing list has discussed the issue across multiple messages. No notable researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking and patch distribution (Red Hat CVE, Ubuntu Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."