An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:4362 https://access.redhat.com/errata/RHSA-2025:4362
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:7422 https://access.redhat.com/errata/RHSA-2025:7422
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:7499 https://access.redhat.com/errata/RHSA-2025:7499