CVE-2023-36664

Name
CVE-2023-36664
Description
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=0974e4f2ac0005d3731e0b5c13ebc7e965540f4d
MISC https://bugs.ghostscript.com/show_bug.cgi?id=706761
MISC https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=505eab7782b429017eb434b2b95120855f2b0e3c
Third Party Advisory https://www.debian.org/security/2023/dsa-5446
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EWMEK2UPCUU3ZLL7VASE5CEHDQY4VKV/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2ICXN5VPF3WJCYKMPSYER5KHTPJXSTJZ/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:* ghostscript >= None <= 10.01.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ghostscript 3.18-main 10.01.2-r0 Cameron Banta <cbanta@gmail.com> possibly vulnerable
ghostscript 3.16-main 9.56.1-r2 Cameron Banta <cbanta@gmail.com> fixed
ghostscript 3.15-main 9.55.0-r2 Cameron Banta <cbanta@gmail.com> fixed
ghostscript 3.17-main 10.01.2-r0 Cameron Banta <cbanta@gmail.com> possibly vulnerable