yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-36664
Component Overview
Vulnerability Overview
Name
CVE-2023-36664
Source
NVD (
link
)
Debian (
link
)
Description
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
CWEs
CWE-552
Published Date
Jun 25, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugs.ghostscript.com/show_bug.cgi?id=706761
Issue Tracking
https://www.debian.org/security/2023/dsa-5446
Third Party Advisory
https://bugs.ghostscript.com/show_bug.cgi?id=706761
Issue Tracking
https://www.debian.org/security/2023/dsa-5446
Third Party Advisory
Analysis
#
Affected Component
Analysis
ghostscript
Patched
Vulnerability Ratings
#
7.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
ghostscript
buildroot
2025.02.x
10.07.0
Not Affected
ghostscript
buildroot
master
10.07.0
Not Affected
ghostscript
yocto
master
10.07.1
Not Affected
ghostscript
yocto
scarthgap
10.05.1
Not Affected
Resolved with patches
#
ghostscript (yocto:kirkstone)
#
Title
Author
Resolve
1
Bug 706778: 706761 revisit
Chris Liddell <chris.liddell@artifex.com>
CVE-2023-36664
2
Bug 706761: Don't "reduce" %pipe% file names for
Chris Liddell <chris.liddell@artifex.com>
CVE-2023-36664