LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:03
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/TeX-Live/texlive-source/releases/tag/build-svn66984 - Release Notes | |
References | () https://gitlab.lisn.upsaclay.fr/texlive/luatex/-/tags/1.17.0 - Release Notes | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RLY43MIRONJSJVNBDFQHQ26MP3JIOB3H/ - | |
References | () https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TF6YXUUFRGBIXIIIEV5SGBJXXT2SMUK5/ - | |
References | () https://tug.org/pipermail/tex-live/2023-May/049188.html - Release Notes | |
References | () https://tug.org/~mseven/luatex.html - Patch, Vendor Advisory |
04 Jun 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
31 May 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
23 May 2023, 18:10
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:luatex_project:luatex:*:*:*:*:*:*:*:* cpe:2.3:a:tug:tex_live:*:*:*:*:*:*:*:* cpe:2.3:a:miktex:miktex:*:*:*:*:*:*:*:* |
|
References | (MISC) https://gitlab.lisn.upsaclay.fr/texlive/luatex/-/tags/1.17.0 - Release Notes | |
References | (MISC) https://tug.org/~mseven/luatex.html - Patch, Vendor Advisory | |
References | (MISC) https://tug.org/pipermail/tex-live/2023-May/049188.html - Release Notes | |
References | (MISC) https://github.com/TeX-Live/texlive-source/releases/tag/build-svn66984 - Release Notes | |
CWE | NVD-CWE-Other | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
20 May 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-05-20 18:15
Updated : 2024-11-21 08:03
NVD link : CVE-2023-32700
Mitre link : CVE-2023-32700
CVE.ORG link : CVE-2023-32700
JSON object : View
Products Affected
miktex
- miktex
luatex_project
- luatex
tug
- tex_live
CWE