
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59801 is a stack-based buffer overflow vulnerability in Artifex GhostXPS affecting all versions before 10.06.0. The flaw resides in the xps_unpredict_tiff function within xpstiff.c, where the samplesperpixel value is not validated before use. It was published on September 22, 2025, and carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat, EUVD).
The root cause is classified as CWE-121 (Stack-based Buffer Overflow), with an estimated CWE-787 (Out-of-bounds Write) also applicable. The vulnerability occurs because the samplesperpixel field in a TIFF image embedded within an XPS document is not bounds-checked before being used in the xps_unpredict_tiff function, allowing a crafted XPS/TIFF file to overflow a stack buffer. The attack vector is local (AV:L), requires no privileges (PR:N) and no user interaction (UI:N), and has a changed scope, indicating potential impact beyond the vulnerable component. A fix is available via the GhostPDL repository commit 99727069197d548a8db69ba5d63f766bff40eaab (EUVD, Ghostscript Bug Tracker).
Successful exploitation results in a low integrity impact with no confidentiality or availability impact, according to the CVSS scoring. The changed scope indicates that the overflow could affect resources or components beyond the GhostXPS process itself, potentially enabling limited unauthorized writes to adjacent memory regions. The practical risk is constrained to scenarios where an attacker can supply a maliciously crafted XPS or TIFF file for processing by a vulnerable GhostXPS instance (Red Hat, EUVD).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-59801. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage exists via Tenable Nessus plugin 265891 (Tenable, EUVD).
samplesperpixel value that exceeds expected bounds.xps_unpredict_tiff function in xpstiff.c reads the unchecked samplesperpixel value and uses it in a stack buffer operation, causing a stack-based buffer overflow.samplesperpixel metadata values in document processing directories.xpstiff.c or xps_unpredict_tiff in stack traces.Artifex has addressed this vulnerability in GhostXPS version 10.06.0. Users should upgrade to GhostXPS 10.06.0 or later as the primary remediation. The specific fix is available in the GhostPDL repository at commit 99727069197d548a8db69ba5d63f766bff40eaab. As a workaround where upgrading is not immediately possible, restrict processing of untrusted XPS or TIFF files through GhostXPS (Ghostscript Bug Tracker, EUVD).
Red Hat has acknowledged the vulnerability and published a security advisory tracking it. Coverage has been noted on automated CVE tracking platforms including Bluesky CVE feeds and vulnerability aggregators. No significant researcher commentary or major media coverage has been identified beyond standard vulnerability database entries (Red Hat).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."