CVE-2025-27835: Buffer Overflow
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs when converting glyphs to Unicode in psi/zbfont.c.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/ghostscriptto a version that resolves this vulnerability.Fixed in 10.0.0~dfsg-11+deb12u7Fixed in 10.05.0~dfsg-1 - Upgrade
Upgrade
Artifex Ghostscriptto a version that resolves this vulnerability.Fixed in 10.05.0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27835?
CVE-2025-27835 is classified as a critical vulnerability due to the potential of a buffer overflow leading to arbitrary code execution.
How do I fix CVE-2025-27835?
To fix CVE-2025-27835, upgrade to Ghostscript version 10.05.0 or later.
Which versions of Ghostscript are affected by CVE-2025-27835?
CVE-2025-27835 affects all versions of Ghostscript prior to 10.05.0.
What type of vulnerability is CVE-2025-27835?
CVE-2025-27835 is a buffer overflow vulnerability that occurs during the conversion of glyphs to Unicode.
Is there a workaround for CVE-2025-27835?
There is no known workaround for CVE-2025-27835; updating to a secure version is recommended.