CVE-2025-27831: Buffer Overflow
An issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to devices/vector/doccommon.c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ghostscriptto a version that resolves this vulnerability.Fixed in 10.0.0~dfsg-11+deb12u7Fixed in 10.05.0~dfsg-1 - Upgrade
Upgrade
Artifex Ghostscriptto a version that resolves this vulnerability.Fixed in 10.05.0 - Compensating control
If you are using the DOCXWRITE or TXTWRITE devices, avoid processing untrusted documents until Ghostscript is upgraded to 10.05.0, since the text buffer overflow occurs via long characters to devices/vector/doc_common.c.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27831?
CVE-2025-27831 is considered a critical vulnerability due to its potential for a text buffer overflow.
How do I fix CVE-2025-27831?
To fix CVE-2025-27831, upgrade to Ghostscript version 10.05.0 or later.
What software is affected by CVE-2025-27831?
CVE-2025-27831 affects versions of Artifex Ghostscript prior to 10.05.0.
What type of vulnerability is CVE-2025-27831?
CVE-2025-27831 is classified as a text buffer overflow vulnerability.
What can happen if CVE-2025-27831 is exploited?
Exploitation of CVE-2025-27831 could lead to arbitrary code execution or application crashes.