CVE-2025-48708: Medium severity ghostscript vulnerability
Published May 23, 2025
·Updated
gslibctxstashsanitizedarg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.
Affected Software
2 affected components
Artifex Ghostscript<10.05.1
Artifex Ghostscript<10.05.1
Remediation
Event History
May 23, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-48708?
CVE-2025-48708 is classified as a moderate severity vulnerability due to its nature of lacking argument sanitization.
2
How do I fix CVE-2025-48708?
To fix CVE-2025-48708, update Artifex Ghostscript to a version beyond 10.05.0 where the issue has been addressed.
3
What are the potential impacts of CVE-2025-48708?
The potential impacts of CVE-2025-48708 include the risk of command injection or unintended behavior during the processing of certain inputs.
4
Which versions of Ghostscript are affected by CVE-2025-48708?
CVE-2025-48708 affects Artifex Ghostscript versions up to and including 10.05.0.
5
Who is the vendor responsible for CVE-2025-48708?
The vendor responsible for CVE-2025-48708 is Artifex, the creator of Ghostscript.