{"id":"CVE-2023-36664","title":"Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).","summary":"Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-552"],"vendor":"artifex","product":"ghostscript","affected":["ghostscript < 10.01.2","debian_linux = 11.0","debian_linux = 12.0","fedora = 37","fedora = 38"],"patched":["ghostscript 10.01.2"],"published":"2023-06-25","updated":"2026-08-27","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-36664","references":[{"url":"https://bugs.ghostscript.com/show_bug.cgi?id=706761","label":"cve@mitre.org"},{"url":"https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=0974e4f2ac0005d3731e0b5c13ebc7e965540f4d","label":"cve@mitre.org"},{"url":"https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=505eab7782b429017eb434b2b95120855f2b0e3c","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ICXN5VPF3WJCYKMPSYER5KHTPJXSTJZ/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5EWMEK2UPCUU3ZLL7VASE5CEHDQY4VKV/","label":"cve@mitre.org"},{"url":"https://security.gentoo.org/glsa/202309-03","label":"cve@mitre.org"},{"url":"https://www.debian.org/security/2023/dsa-5446","label":"cve@mitre.org"},{"url":"https://bugs.ghostscript.com/show_bug.cgi?id=706761","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=0974e4f2ac0005d3731e0b5c13ebc7e965540f4d","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=505eab7782b429017eb434b2b95120855f2b0e3c","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ICXN5VPF3WJCYKMPSYER5KHTPJXSTJZ/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5EWMEK2UPCUU3ZLL7VASE5CEHDQY4VKV/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202309-03","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2023/dsa-5446","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.04243,"epssPercentile":0.90619,"ingestedAt":"2026-08-27T19:06:56.508Z","exploits":{"github":4,"githubRepos":["https://github.com/jakabakos/CVE-2023-36664-Ghostscript-command-injection","https://github.com/winkler-winsen/Scan_GhostScript","https://github.com/jeanchpt/CVE-2023-36664"],"checkedAt":"2026-09-21T15:25:51.495Z"},"exploitAvailable":true,"slug":"CVE-2023-36664","body":"## Overview\n\nArtifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).\n\n## Affected\n\n- `ghostscript < 10.01.2`\n- `debian_linux = 11.0`\n- `debian_linux = 12.0`\n- `fedora = 37`\n- `fedora = 38`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `ghostscript 10.01.2`","depth":"midnight","depthScore":56,"depthScoreParts":{"impact":42.9,"likelihood":0.8,"exploitation":12,"ransomware":0},"changes":[{"seq":4654,"id":"CVE-2023-36664","ts":1788887197316,"field":"exploit_available","old":"false","new":"true"},{"seq":3537,"id":"CVE-2023-36664","ts":1788886313401,"field":"exploit_available","old":"true","new":"false"},{"seq":2391,"id":"CVE-2023-36664","ts":1788882982707,"field":"exploit_available","old":"false","new":"true"},{"seq":1420,"id":"CVE-2023-36664","ts":1788882395601,"field":"exploit_available","old":"true","new":"false"},{"seq":534,"id":"CVE-2023-36664","ts":1788881831728,"field":"exploit_available","old":"false","new":"true"}]}