CVE-2023-36664

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-36664
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-36664.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-36664
Related
Published
2023-06-25T22:15:21Z
Modified
2025-01-14T11:48:26.385927Z
Downstream
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

References

Affected packages

Alpine:v3.15 / ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.55.0-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1
9.26-r2
9.27-r0
9.27-r1
9.27-r2
9.27-r3
9.27-r4
9.50-r0
9.51-r0
9.52-r0
9.53.1-r0
9.53.2-r0
9.53.3-r0
9.54.0-r0
9.54.0-r1
9.55.0-r0
9.55.0-r1

Alpine:v3.16 / ghostscript

Package

Name
ghostscript
Purl
pkg:apk/alpine/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.56.1-r2

Affected versions

8.*

8.64-r0
8.70-r0
8.71-r0
8.71-r1
8.71-r2
8.71-r3
8.71-r4

9.*

9.00-r0
9.00-r1
9.00-r2
9.04-r0
9.05-r0
9.05-r1
9.06-r0
9.06-r1
9.06-r2
9.06-r3
9.07-r0
9.09-r0
9.09-r1
9.10-r0
9.10-r1
9.15-r0
9.15-r1
9.16-r0
9.16-r1
9.16-r2
9.18-r0
9.19-r0
9.19-r1
9.20-r0
9.20-r1
9.21-r0
9.21-r1
9.21-r2
9.21-r3
9.22-r0
9.24-r0
9.25-r0
9.25-r1
9.26-r0
9.26-r1
9.26-r2
9.27-r0
9.27-r1
9.27-r2
9.27-r3
9.27-r4
9.50-r0
9.51-r0
9.52-r0
9.53.1-r0
9.53.2-r0
9.53.3-r0
9.54.0-r0
9.54.0-r1
9.55.0-r0
9.56.1-r0
9.56.1-r1

Debian:11 / ghostscript

Package

Name
ghostscript
Purl
pkg:deb/debian/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.53.3~dfsg-7+deb11u5

Affected versions

9.*

9.53.3~dfsg-7
9.53.3~dfsg-7+deb11u1
9.53.3~dfsg-7+deb11u2
9.53.3~dfsg-7+deb11u3
9.53.3~dfsg-7+deb11u4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / ghostscript

Package

Name
ghostscript
Purl
pkg:deb/debian/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.0.0~dfsg-11+deb12u1

Affected versions

10.*

10.0.0~dfsg-11

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / ghostscript

Package

Name
ghostscript
Purl
pkg:deb/debian/ghostscript?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
10.01.2~dfsg-1

Affected versions

10.*

10.0.0~dfsg-11

Ecosystem specific

{
    "urgency": "not yet assigned"
}