gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript
before 10.05.1 lacks argument sanitization for the # case. A created PDF
document includes its password in cleartext. (CVE-2025-48708)
- https://bugs.mageia.org/show_bug.cgi?id=34307
- https://www.openwall.com/lists/oss-security/2025/05/23/2
- https://www.cve.org/CVERecord?id=CVE-2025-48708
- 9/core/ghostscript-10.05.1-1.mga9
Get the latest Linux and open source security news straight to your inbox.