CVE-2025-27837: Path Traversal
Published Mar 25, 2025
·Updated
An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gpmswin.c and base/winrtsup.cpp.
Affected Software
2 affected components
Artifex ghostscript<10.05.0
Artifex ghostscript<10.05.0
Remediation
Patch Available
Event History
Mar 25, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-27837?
CVE-2025-27837 is considered a moderate severity vulnerability due to its potential to allow access to arbitrary files.
2
How do I fix CVE-2025-27837?
To fix CVE-2025-27837, upgrade to Ghostscript version 10.05.0 or later.
3
What type of vulnerability is CVE-2025-27837?
CVE-2025-27837 is a path traversal vulnerability that can exploit invalid UTF-8 characters.
4
Which software versions are affected by CVE-2025-27837?
CVE-2025-27837 affects all versions of Artifex Ghostscript prior to 10.05.0.
5
What can attackers achieve with CVE-2025-27837?
Attackers can potentially access arbitrary files on the system due to the vulnerability in CVE-2025-27837.