CVE-2025-46646
CVSS 3.1 Score 4.5 of 10 (medium)
Details
Published Apr 26, 2025
Updated: Apr 29, 2025
CWE ID 24
Summary
CVE-2025-46646 is a newly identified vulnerability in Artifex Ghostscript before version 10.05.0. This issue involves the mishandling of overlong UTF-8 encoding in the decode_utf8 function of base/gp_utf8.c. Notably, this vulnerability stems from an incomplete fix for the previous issue, CVE-2024-46954. This vulnerability could potentially be exploited by malicious actors to execute arbitrary code or cause denial-of-service conditions. System administrators are advised to update their Ghostscript installations as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GhostScript
Affected Vendors
- Artifex