CVE-2019-25059: High severity ghostscript vulnerability
Published Apr 25, 2022
·Updated
Artifex Ghostscript through 9.26 mishandles .completefont. NOTE: this issue exists because of an incomplete fix for CVE-2019-3839.
Affected Software
2 affected components
Artifex Ghostscript<=9.26
Debian Debian Linux=9.0
Remediation
Event History
Apr 25, 2022
CVE Published
via MITRE·03:29 AM
Data Sourced
via MITRE·03:29 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Artifex Ghostscript issue?
The vulnerability ID for this Artifex Ghostscript issue is CVE-2019-25059.
2
What is the severity of CVE-2019-25059?
The severity of CVE-2019-25059 is high, with a severity value of 7.8.
3
What software is affected by CVE-2019-25059?
Artifex Ghostscript version 9.26 and Debian Linux version 9.0 are affected by CVE-2019-25059.
4
What is the cause of CVE-2019-25059?
CVE-2019-25059 is caused by Artifex Ghostscript mishandling .completefont.
5
Is there a fix for CVE-2019-25059?
Yes, a fix for CVE-2019-25059 exists. Please refer to the provided references for more information.