ZeroHour

CVE-2023-36664

CVSS 3.1
7.8 high
EPSS
4%p91
Published
()
Modified
Description

Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

Vendors
artifexdebianfedoraproject
Products
ghostscript, debian linux, fedora
Weakness
CWE-552
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news