First published: Mon Apr 25 2022(Updated: )
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Software Ghostscript | <=9.26 | |
Debian Debian Linux | =9.0 |
http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=430e219ea17a2650577d70021399c4ead05869e0
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Artifex Ghostscript issue is CVE-2019-25059.
The severity of CVE-2019-25059 is high, with a severity value of 7.8.
Artifex Ghostscript version 9.26 and Debian Linux version 9.0 are affected by CVE-2019-25059.
CVE-2019-25059 is caused by Artifex Ghostscript mishandling .completefont.
Yes, a fix for CVE-2019-25059 exists. Please refer to the provided references for more information.