First published: Tue Mar 25 2025(Updated: )
An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and base/winrtsup.cpp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ghostscript | <10.05.0 | |
Ghostscript | <10.05.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27837 is considered a moderate severity vulnerability due to its potential to allow access to arbitrary files.
To fix CVE-2025-27837, upgrade to Ghostscript version 10.05.0 or later.
CVE-2025-27837 is a path traversal vulnerability that can exploit invalid UTF-8 characters.
CVE-2025-27837 affects all versions of Artifex Ghostscript prior to 10.05.0.
Attackers can potentially access arbitrary files on the system due to the vulnerability in CVE-2025-27837.