LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.
References
Configurations
Configuration 1 (hide)
|
History
07 Nov 2023, 04:14
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
04 Jun 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
31 May 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2023-05-20 18:15
Updated : 2024-02-28 20:13
NVD link : CVE-2023-32700
Mitre link : CVE-2023-32700
CVE.ORG link : CVE-2023-32700
JSON object : View
Products Affected
miktex
- miktex
luatex_project
- luatex
tug
- tex_live
CWE