Multiple vulnerabilities were discovered in ghostcript, an interpreter for the PostScript language and PDF
Multiple vulnerabilities were discovered in ghostcript, an interpreter
for the PostScript language and PDF.
CVE-2025-7462
Function pdf_ferror of the file devices/vector/gdevpdf.c of the
component New Output File Open Error Handler. The manipulation
leads to null pointer dereference. It is possible to initiate the
attack remotely.
CVE-2025-59798
A stack-based buffer overflow in pdf_write_cmap in
devices/vector/gdevpdtw.c.
CVE-2025-59799
a stack-based buffer overflow in pdfmark_coerce_dest in
devices/vector/gdevpdfm.c via a large size value.
For Debian 11 bullseye, these problems have been fixed in version
9.53.3~dfsg-7+deb11u11.
We recommend that you upgrade your ghostscript packages.
For the detailed security status of ghostscript please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/ghostscript
Further information about Debian LTS security advisories, how to apply
Get the latest Linux and open source security news straight to your inbox.