CVE-2025-46646

CVSS 3.1 Score 4.5 of 10 (medium)

Details

Published Apr 26, 2025
Updated: Apr 29, 2025
CWE ID 24

Summary

CVE-2025-46646 is a newly identified vulnerability in Artifex Ghostscript before version 10.05.0. This issue involves the mishandling of overlong UTF-8 encoding in the decode_utf8 function of base/gp_utf8.c. Notably, this vulnerability stems from an incomplete fix for the previous issue, CVE-2024-46954. This vulnerability could potentially be exploited by malicious actors to execute arbitrary code or cause denial-of-service conditions. System administrators are advised to update their Ghostscript installations as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share