Alerts This Week
Warning Icon 1 774
Alerts This Week
Warning Icon 1 774

Debian LTS: Ghostscript Medium Buffer Overflow CVE-2025-7462 DLA-4330-1

debian lts
Calendar Grey October 14, 2025
Dist Debian Esm H88
Discover the security update DLA-4330-1 for Ghostscript addressing multiple vulnerabilities impacting Debian systems. Upgrade recommended.

Multiple vulnerabilities were discovered in ghostcript, an interpreter for the PostScript language and PDF

Summary

Multiple vulnerabilities were discovered in ghostcript, an interpreter
for the PostScript language and PDF.

CVE-2025-7462

Function pdf_ferror of the file devices/vector/gdevpdf.c of the
component New Output File Open Error Handler. The manipulation
leads to null pointer dereference. It is possible to initiate the
attack remotely.

CVE-2025-59798

A stack-based buffer overflow in pdf_write_cmap in
devices/vector/gdevpdtw.c.

CVE-2025-59799

a stack-based buffer overflow in pdfmark_coerce_dest in
devices/vector/gdevpdfm.c via a large size value.

For Debian 11 bullseye, these problems have been fixed in version
9.53.3~dfsg-7+deb11u11.

We recommend that you upgrade your ghostscript packages.

For the detailed security status of ghostscript please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/ghostscript

Further information about Debian LTS security advisories, how to apply

Read the Full Advisory


Severity
medium
Lowest
Low
Medium
High
Critical

Package: ghostscript
Version: 9.53.3~dfsg-7+deb11u11
CVE ID: CVE-2025-7462 CVE-2025-59798 CVE-2025-59799

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here