Heap-based Buffer Overflow in Artifex Ghostscript Products
CVE-2025-59800

4.3MEDIUM

Key Information:

Vendor

Artifex

Vendor
CVE Published:
22 September 2025

What is CVE-2025-59800?

An integer overflow in the ocr_begin_page function of devices/gdevpdfocr.c in Artifex Ghostscript versions through 10.05.1 can lead to a heap-based buffer overflow in ocr_line8. This vulnerability exposes applications using Ghostscript to potential memory corruption, which can be exploited by attackers to manipulate program execution or access sensitive information.

Affected Version(s)

Ghostscript 0 <= 10.05.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59800 : Heap-based Buffer Overflow in Artifex Ghostscript Products