Select your cookie preferences

We use cookies and similar tools to enhance your experience, provide our services, deliver relevant advertising, and make improvements. Approved third parties also use these tools to help us deliver advertising and provide certain site features.

CVE-2025-27831

Public on 2025-03-21
Modified on 2025-03-21
Description

Text buffer overflow with long characters; the txt_get_unicode function was copying too few bytes from the fixed glyph name to unicode mapping tables. This was probably causing incorrect Unicode code points in relatively rare cases but not otherwise a problem. However, a badly formed GlyphNames2Unicode array attached to a font could cause the decoding to spill over the assigned buffer.

Patched in ghostpdl-10.05.0

Severity
Important
See what this means
CVSS v3 Base Score
8.4
See breakdown
Continue reading

Affected Packages

Platform Package Release Date Advisory
Amazon Linux 2 - Core ghostscript 2025-03-26 19:24 ALAS2-2025-2805
Amazon Linux 2023 ghostscript 2025-03-26 20:44 ALAS2023-2025-908

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H