CVE-2025-48708 ghostscript: Ghostscript Argument Sanitization Vulnerability (fedora#2368148, fedora#2368134). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-5be02d3285 2025-06-08 02:30:29.771849+00:00 -------------------------------------------------------------------------------- Name : ghostscript Product : Fedora 41 Version : 10.03.1 Release : 7.fc41 URL : https://ghostscript.com/ Summary : Interpreter for PostScript language & PDF Description : This package provides useful conversion utilities based on Ghostscript software, for converting PS, PDF and other document formats between each other. Ghostscript is a suite of software providing an interpreter for Adobe Systems' PostScript (PS) and Portable Document Format (PDF) page description languages. Its primary purpose includes displaying (rasterization & rendering) and printing of document pages, as well as conversions between different document formats. -------------------------------------------------------------------------------- Update Information: CVE-2025-48708 ghostscript: Ghostscript Argument Sanitization Vulnerability (fedora#2368148, fedora#2368134) -------------------------------------------------------------------------------- ChangeLog: * Tue May 27 2025 Zdenek Dohnal - 10.03.1-7 - CVE-2025-48708 ghostscript: Ghostscript Argument Sanitization Vulnerability (fedora#2368148, fedora#2368134) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2368134 - CVE-2025-48708 Ghostscript: Ghostscript Argument Sanitization Vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=2368134 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-5be02d3285' at the command line. For more information, refer to the dnfdocumentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext. (CVE-2025-48708) References: . MGASA-2025-0170 - Updated ghostscript packages fix security vulnerabilities Publication date: 28 May 2025 URL: https://advisories.mageia.org/MGASA-2025-0170.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-48708 gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext. (CVE-2025-48708) References: - https://bugs.mageia.org/show_bug.cgi?id=34307 - https://www.openwall.com/lists/oss-security/2025/05/23/2 - https://www.cve.org/CVERecord?id=CVE-2025-48708 SRPMS: - 9/core/ghostscript-10.05.1-1.mga9 . Revised ghostscript packages fix security flaws in PDFs that could compromise passwords, impacting Mageia 9 users.. Ghostscript Security, PDF Password Exposure, Mageia Update. . Severity: Critical. LinuxSecurity.com Team
In rsync, a remote file-copying tool, remote attackers were able to bypass the argument-sanitization protection mechanism by passing additional --protect-args. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2833-1
Get the latest Linux and open source security news straight to your inbox.