ghostscript: vulnerable to OS command injection due to mishandles permission validation for pipe devices
Published Jun 25, 2023
8.4
HIGHCVSS 3.1
EPSS 4.01%
Description
Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
Affected products
No data.
Configuration 1
- < 10.01.2
Configuration 2
- 11.0
- 12.0
Configuration 3
- 37
- 38
No data.
Red Hat Enterprise Linux 9
ghostscript-0:9.54.0-10.el9_2
Fixed · RHSA-2023:5459
Red Hat Enterprise Linux 9.0 Extended Update Support
ghostscript-0:9.54.0-7.el9_0.1
Fixed · RHSA-2023:4324
Red Hat Enterprise Linux 6
ghostscript
Out of support scope
Red Hat Enterprise Linux 7
ghostscript
Not affected
Red Hat Enterprise Linux 8
ghostscript
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 9 | ghostscript-0:9.54.0-10.el9_2 | Fixed | RHSA-2023:5459 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | ghostscript-0:9.54.0-7.el9_0.1 | Fixed | RHSA-2023:4324 |
| Red Hat Enterprise Linux 6 | ghostscript | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | ghostscript | Not affected | n/a |
| Red Hat Enterprise Linux 8 | ghostscript | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Versions of Ghostscript shipped with Red Hat Enterprise Linux 7 and 8 are not affected as it will forbid file execution with ".invalidfileaccess" if -dSAFER is used.
References (18)
- https://access.redhat.com/security/cve/CVE-2023-36664 Vendor Advisory
- https://artifex.com/blog/security-vulnerability-fixed-in-ghostscript-10.01.2
- https://bugs.ghostscript.com/show_bug.cgi?id=706761 Issue TrackingPermissions Required
- https://bugzilla.redhat.com/show_bug.cgi?id=2217798 Issue Tracking
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=0974e4f2ac0005d3731e0b5c13ebc7e965540f4d Permissions Required
- https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=505eab7782b429017eb434b2b95120855f2b0e3c Permissions Required
- https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=0974e4f2ac0005d3731e0b5c13ebc7e965540f4d
- https://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=505eab7782b429017eb434b2b95120855f2b0e3c
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ICXN5VPF3WJCYKMPSYER5KHTPJXSTJZ/ Broken Link
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5EWMEK2UPCUU3ZLL7VASE5CEHDQY4VKV/ Broken Link
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2ICXN5VPF3WJCYKMPSYER5KHTPJXSTJZ/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5EWMEK2UPCUU3ZLL7VASE5CEHDQY4VKV/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-36664
- https://security-tracker.debian.org/tracker/CVE-2023-36664
- https://security.gentoo.org/glsa/202309-03 vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-36664
- https://www.debian.org/security/2023/dsa-5446 vendor-advisoryThird Party Advisory
- https://www.kroll.com/en/publications/cyber/ghostscript-cve-2023-36664-remote-code-execution-vulnerability
Change history (0)
No recorded changes yet.