CVE-2025-48708

Published May 23, 2025

Last updated 16 days ago

CVSS medium 4.0
Artifex Ghostscript

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-48708 affects Artifex Ghostscript versions through 10.05.0 (and before 10.05.1 according to some sources). The vulnerability lies in the `gs_lib_ctx_stash_sanitized_arg` function within the `base/gslibctx.c` file. This function lacks proper argument sanitization for the '#' case. Due to this lack of sanitization, a created PDF document may include its password in cleartext. This could expose sensitive information if the PDF is shared or stored without proper protection.

Description
gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.
Source
cve@mitre.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
4
Impact score
1.4
Exploitability score
2.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity
MEDIUM

Weaknesses

cve@mitre.org
CWE-212

Social media

Hype score
Not currently trending