Skip to main content
Skip table of contents

ISN 2023-13: IGEL OS Ghostscript Vulnerability

First published 24 July 2023

CVSS 3.1: 7.8 (High)



A vulnerability has been discovered in Ghostscript, a Postscript and PDF library used in IGEL OS. This affects the following IGEL products:

  • IGEL OS 12

  • IGEL OS 11


A security issue rated high has been found in Ghostscript (CVE-2023-36664). The software mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix). Abusing this, an attacker can achieve command execution with malformed documents that are processed by Ghostscript, e.g. Postscript, PDF and EPS files.


  • General: Until this issue is fixed, print and view only documents from trustworthy sources.

  • OS 11: If local printing from IGEL OS is not needed, you can remove Ghostscript from the system using a UMS profile:

  1. In Setup, go to System > Firmware Customization > Features.

  2. Disable the entries for Printing (Internet Printing Protocol CUPS), PrinterLogic, and NoMachine NX.

  3. Apply and Save the changes.

  4. Reboot the devices.

Update Instructions

  • OS 12: Update the IGEL OS Base System app to version 12.02.100 (available in September 2023)

  • OS 11: Update to IGEL OS 11.09.100 (available in September 2023)


JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.