Home

Description

gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript before 10.05.1 lacks argument sanitization for the # case. A created PDF document includes its password in cleartext.

PUBLISHED Reserved 2025-05-23 | Published 2025-05-23 | Updated 2025-05-24 | Assigner mitre




MEDIUM: 4.0CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-212 Improper Removal of Sensitive Information Before Storage or Transfer

Product status

Default status
unaffected

Any version before 10.05.1
affected

References

www.openwall.com/lists/oss-security/2025/05/23/2

bugs.ghostscript.com/show_bug.cgi?id=708446

cgit.ghostscript.com/...663c623b4462f9e78686a31fd880207303ee

cve.org (CVE-2025-48708)

nvd.nist.gov (CVE-2025-48708)

Download JSON