Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Fedora 41: FedPA-2025-47818d27ba critical: ghostscript buffer overflow

fedora
Calendar Grey April 5, 2025
Dist Fedora Esm H88
The recent Ghostscript upgrade for Fedora 41 addresses vulnerabilities related to buffer overflows, tackling multiple CVEs. Find all the updated information here.
CVE-2025-27835 ghostscript: Buffer overflow when converting glyphs to unicode (fedora#2355026) CVE-2025-27834 ghostscript: Buffer overflow caused by an oversized Type 4 function in...

Summary

This package provides useful conversion utilities based on Ghostscript software,

for converting PS, PDF and other document formats between each other.

Ghostscript is a suite of software providing an interpreter for Adobe Systems'

PostScript (PS) and Portable Document Format (PDF) page description languages.

Its primary purpose includes displaying (rasterization & rendering) and printing

of document pages, as well as conversions between different document formats.

Update Information:

CVE-2025-27835 ghostscript: Buffer overflow when converting glyphs to unicode (fedora#2355026) CVE-2025-27834 ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF (fedora#2355024) CVE-2025-27832 ghostscript: NPDL device: Compression buffer overflow (fedora#2355022) CVE-2025-27836 ghostscript: device: Print buffer overflow (fedora#2355020) CVE-2025-27830 ghostscript: Buffer overflow during serialization of DollarBlend in font (fedora#2355016) CVE-2025-27833 ghostscript: Buffer overflow with long TTF font name (fedora#2355012) CVE-2025-27837 ghostscript: Access to arbitrary files through truncated path with invalid UTF-8 (fedora#2355010) CVE-2025-27831 ghostscript: Text buffer overflow with long characters (fedora#2355008)

Change Log

* Fri Mar 28 2025 Zdenek Dohnal - 10.03.1-5 - CVE-2025-27835 ghostscript: Buffer overflow when converting glyphs to unicode (fedora#2355026) - CVE-2025-27834 ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF (fedora#2355024) - CVE-2025-27832 ghostscript: NPDL device: Compression buffer overflow (fedora#2355022) - CVE-2025-27836 ghostscript: device: Print buffer overflow (fedora#2355020) - CVE-2025-27830 ghostscript: Buffer overflow during serialization of DollarBlend in font (fedora#2355016) - CVE-2025-27833 ghostscript: Buffer overflow with long TTF font name (fedora#2355012) - CVE-2025-27837 ghostscript: Access to arbitrary files through truncated path with invalid UTF-8 (fedora#2355010) - CVE-2025-27831 ghostscript: Text buffer overflow with long characters (fedora#2355008)

References


[ 1 ] Bug #2354947 - CVE-2025-27835 Ghostscript: Buffer overflow when converting glyphs to unicode https://bugzilla.redhat.com/show_bug.cgi?id=2354947 [ 2 ] Bug #2354948 - CVE-2025-27834 Ghostscript: Buffer overflow caused by an oversized Type 4 function in a PDF https://bugzilla.redhat.com/show_bug.cgi?id=2354948 [ 3 ] Bug #2354949 - CVE-2025-27832 Ghostscript: NPDL device: Compression buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=2354949 [ 4 ] Bug #2354952 - CVE-2025-27836 Ghostscript: device: Print buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=2354952 [ 5 ] Bug #2354953 - CVE-2025-27830 Ghostscript: Buffer overflow during serialization of DollarBlend in font https://bugzilla.redhat.com/show_bug.cgi?id=2354953 [ 6 ] Bug #2354954 - CVE-2025-27833 Ghostscript: Buffer overflow with long TTF font name https://bugzilla.redhat.com/show_bug.cgi?id=2354954 [ 7 ] Bug #2354961 - CVE-2025-27...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-47818d27ba' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ghostscript
Product: Fedora 41
Version: 10.03.1
Release: 5.fc41
Summary: Interpreter for PostScript language & PDF

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here