CVE-2023-32700
Summary
| CVE | CVE-2023-32700 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-20 18:15:00 UTC |
| Updated | 2023-11-07 04:14:00 UTC |
| Description | LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| luatex-1.17.0 update - tex-live mailing list - TeX Users Group | MISC | tug.org | |
| [SECURITY] Fedora 37 Update: texlive-base-20210325-54.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| 1.17.0 · Tags · TeXLive / luatex · GitLab | MISC | gitlab.lisn.upsaclay.fr | |
| [SECURITY] Fedora 38 Update: texlive-base-20220321-72.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Release Rebuild TL2023 for luatex · TeX-Live/texlive-source · GitHub | MISC | github.com | |
| LuaTeX Security Vulnerabilities | MISC | tug.org | |
| [SECURITY] Fedora 38 Update: texlive-base-20220321-72.fc38 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 37 Update: texlive-base-20210325-54.fc37 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160747 Oracle Enterprise Linux Security Update for texlive (ELSA-2023-3661)
- 181792 Debian Security Update for texlive-bin (DSA 5406-1)
- 181793 Debian Security Update for texlive-bin (DLA 3427-1)
- 181817 Debian Security Update for texlive-bin (DLA 3427-2)
- 184915 Debian Security Update for texlive-bin (CVE-2023-32700)
- 199373 Ubuntu Security Notification for TeX Live Vulnerability (USN-6115-1)
- 241727 Red Hat Update for texlive (RHSA-2023:3661)
- 284013 Fedora Security Update for texlive (FEDORA-2023-d261122726)
- 284095 Fedora Security Update for texlive (FEDORA-2023-38094d905c)
- 503270 Alpine Linux Security Update for texlive
- 506258 Alpine Linux Security Update for texlive
- 754037 SUSE Enterprise Linux Security Update for texlive (SUSE-SU-2023:2285-1)
- 754040 SUSE Enterprise Linux Security Update for cups-filters, poppler, texlive (SUSE-SU-2023:2287-1)
- 941149 AlmaLinux Security Update for texlive (ALSA-2023:3661)
- 960944 Rocky Linux Security Update for texlive (RLSA-2023:3661)