LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:03
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/TeX-Live/texlive-source/releases/tag/build-svn66984 - Release Notes | |
References | () https://gitlab.lisn.upsaclay.fr/texlive/luatex/-/tags/1.17.0 - Release Notes | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RLY43MIRONJSJVNBDFQHQ26MP3JIOB3H/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TF6YXUUFRGBIXIIIEV5SGBJXXT2SMUK5/ - | |
References | () https://tug.org/pipermail/tex-live/2023-May/049188.html - Release Notes | |
References | () https://tug.org/~mseven/luatex.html - Patch, Vendor Advisory |
07 Nov 2023, 04:14
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
04 Jun 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
31 May 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2023-05-20 18:15
Updated : 2024-11-21 08:03
NVD link : CVE-2023-32700
Mitre link : CVE-2023-32700
CVE.ORG link : CVE-2023-32700
JSON object : View
Products Affected
tug
- tex_live
miktex
- miktex
luatex_project
- luatex
CWE