Vulnerability Description
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Artifex | Ghostscript | <= 10.01.2 |
| Debian | Debian Linux | 11.0 |
| Fedoraproject | Fedora | 37 |
Related Weaknesses (CWE)
References
- https://bugs.ghostscript.com/show_bug.cgi?id=706761Issue TrackingPermissions Required
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=0974e4f2ac0005d3731e0
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=505eab7782b429017eb43
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202309-03
- https://www.debian.org/security/2023/dsa-5446Third Party Advisory
- https://bugs.ghostscript.com/show_bug.cgi?id=706761Issue TrackingPermissions Required
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=0974e4f2ac0005d3731e0
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=505eab7782b429017eb43
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202309-03
- https://www.debian.org/security/2023/dsa-5446Third Party Advisory
FAQ
What is CVE-2023-36664?
CVE-2023-36664 is a vulnerability with a CVSS score of 7.8 (HIGH). Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
How severe is CVE-2023-36664?
CVE-2023-36664 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-36664?
Check the references section above for vendor advisories and patch information. Affected products include: Artifex Ghostscript, Debian Debian Linux, Fedoraproject Fedora.