CVE-2023-36664

Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
Configurations

Configuration 1 (hide)

cpe:2.3:a:artifex:ghostscript:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

History

05 Dec 2024, 15:15

Type Values Removed Values Added
CWE CWE-552

Information

Published : 2023-06-25 22:15

Updated : 2024-12-05 15:15


NVD link : CVE-2023-36664

Mitre link : CVE-2023-36664

CVE.ORG link : CVE-2023-36664


JSON object : View

Products Affected

fedoraproject

  • fedora

artifex

  • ghostscript

debian

  • debian_linux
CWE
NVD-CWE-Other CWE-552

Files or Directories Accessible to External Parties