Pstotext is a utility for extracting text from PostScript and PDF documents, occupying a narrow but established niche in document-processing tooling. The sparse signal available centers on the product's file-parsing role and the inherent complexity of handling untrusted document formats; current severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pstotext over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2536HIGH pstotext before 1.8g does not properly use the "-dSAFER" option when calling Ghostscript to extract plain text from PostScript and PDF files, which allows remote attackers to execu | Aug 10, 2005 | 7.5 | 20 | NO | NO |
CVE-2006-5869MEDIUM pstotext before 1.9 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a file name. | Nov 26, 2006 | 5.1 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pstotext.
Media articles that mention a CVE ID that affects a product developed by Pstotext — matched by CVE ID, not by vendor name.