CVE-2023-36664: Artifex Ghostscript
High severity, CVSS 7.8. EPSS: 3.9% chance of exploitation in the next 30 days.
Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
Affected products
- Artifex Ghostscript: before 10.01.2 (fixed in 10.01.2)
- Debian Debian Linux: version 11.0 only; version 12.0 only
- Fedoraproject Fedora: version 37 only; version 38 only
Published 2023-06-25. Last modified 2026-08-28.