Opened 17 months ago

Closed 17 months ago

Last modified 16 months ago

#21517 closed enhancement (fixed)

ghostscript-10.05.1 (Security release)

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: elevated Milestone: 12.4
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (5)

comment:1 by Bruce Dubbs, 17 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:2 by Bruce Dubbs, 17 months ago

Summary: ghostscript-10.05.1 → ghostscript-10.05.1 (Security release)

ersion 10.05.1 (2025-04-29)

Highlights in this release include:

  • The 10.05.1 patch release addresses:
    • An overflow issue in Freetype on platforms where long is a 4 byte (rather than 8 byte) type (Microsoft Windows, for example) causing corrupted glyph rendering at higher resolutions
      • An issue with embedded files, affecting Zugferd format PDF creation.
      • Broken logic in PDF Optional Content processing
      • Potential slow down due to searching for identifiable font files
      • A small number of extreme edge case segmentation faults.

  • This release addresses CVEs: CVE-2025-27835, CVE-2025-27832, CVE-2025-27831, CVE-2025-27836, CVE-2025-27830, CVE-2025-27833, CVE-2025-27837, CVE-2025-27834, CVE-2025-46646
  • The 10.05.1 release deprecates the non-standard operator "selectdevice", all code should now be using the standard "setpagedevice" operator. "selectdevice" will be removed in the 10.06.0 release.
  • We now support production of PDF/X-1a and PDF/X-4a in addition to the existing support for PDF/X-3
  • Our efforts in code hygiene and maintainability continue.
  • The usual round of bug fixes, compatibility changes, and incremental improvements.

Incompatible changes

  • (10.05.1) The 10.05.1 release deprecates the non-standard operator "selectdevice", all code should now be using the standard "setpagedevice" operator. "selectdevice" will be removed in the 10.06.0 release.

comment:3 by Bruce Dubbs, 17 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at commits

1d8671328f Update to fltk-1.4.3.
eca8cf4d9e Update to ghostscript-10.05.1 (Security release).
8f41b7b60a Update to pixman-0.46.0.
45d1de2874 Update to smartmontools-7.5.

comment:4 by Douglas R. Reno, 16 months ago

We now have one 10.05.1 specific security fix, so the security advisory will need to be updated.

https://www.cve.org/CVERecord?id=CVE-2025-48708 was published today with
this description:

   gs_lib_ctx_stash_sanitized_arg in base/gslibctx.c in Artifex Ghostscript
   before 10.05.1 lacks argument sanitization for the # case. A created PDF
   document includes its password in cleartext.

The bug report at https://bugs.ghostscript.com/show_bug.cgi?id=708446 says:

   When generating a password-protected PDF using the latest version of the tool
   on Windows 10, I noticed that the full command-line input, including the
   plaintext password, is embedded at the beginning of the generated PDF file.
   This allows anyone with access to the PDF to retrieve the password simply by
   running a command like "type" (Windows) or "cat" (Linux/macOS) on the file.

The fix included in the 10.05.1 release appears to be:

https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/commit/?h=gs10.05.1&id=5b5968c306b3e35cdeec83bb15026fd74a7334de

A quick summary is that ghostscript can embed passwords in plaintext inside of encrypted PDF files.

comment:5 by Douglas R. Reno, 16 months ago

Priority: normal → elevated
Note: See TracTickets for help on using tickets.