{
  "threat_severity" : "Moderate",
  "public_date" : "2025-03-25T00:00:00Z",
  "bugzilla" : {
    "description" : "Ghostscript: NPDL device: Compression buffer overflow",
    "id" : "2354949",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2354949"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "cwe" : "CWE-120",
  "details" : [ "An issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.", "A flaw was found in Artifex Ghostscript. The NPDL device has a compression buffer overflow for contrib/japanese/gdevnpdl.c." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2025-05-14T00:00:00Z",
    "advisory" : "RHSA-2025:7593",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.0",
    "package" : "ghostscript-0:10.02.1-16.el10_0"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2025-06-03T00:00:00Z",
    "advisory" : "RHSA-2025:8421",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "ghostscript-0:9.27-17.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2025-05-14T00:00:00Z",
    "advisory" : "RHSA-2025:7586",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "ghostscript-0:9.54.0-19.el9_6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
    "release_date" : "2025-12-15T00:00:00Z",
    "advisory" : "RHSA-2025:23153",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.0",
    "package" : "ghostscript-0:9.54.0-7.el9_0.4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions",
    "release_date" : "2025-12-09T00:00:00Z",
    "advisory" : "RHSA-2025:22869",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.2",
    "package" : "ghostscript-0:9.54.0-12.el9_2.3"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.4 Extended Update Support",
    "release_date" : "2025-11-24T00:00:00Z",
    "advisory" : "RHSA-2025:21915",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.4",
    "package" : "ghostscript-0:9.54.0-17.el9_4.1"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Fix deferred",
    "package_name" : "ghostscript",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Fix deferred",
    "package_name" : "ghostscript",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-27832\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-27832\nhttps://bugs.ghostscript.com/show_bug.cgi?id=708133" ],
  "name" : "CVE-2025-27832",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}