Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
References
| Link | Resource |
|---|---|
| https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=0974e4f2ac0005d3731e0b5c13ebc7e965540f4d | Mailing List Patch |
| https://bugs.ghostscript.com/show_bug.cgi?id=706761 | Issue Tracking Permissions Required |
| https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=505eab7782b429017eb434b2b95120855f2b0e3c | Mailing List Patch |
| https://www.debian.org/security/2023/dsa-5446 | Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EWMEK2UPCUU3ZLL7VASE5CEHDQY4VKV/ | Mailing List |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2ICXN5VPF3WJCYKMPSYER5KHTPJXSTJZ/ | Mailing List |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2023-06-25 22:15
Updated : 2023-08-02 15:42
NVD link : CVE-2023-36664
Mitre link : CVE-2023-36664
JSON object : View
Products Affected
fedoraproject
- fedora
debian
- debian_linux
artifex
- ghostscript
CWE
