Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-32700

Опубликовано: 20 мая 2023
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

An arbitrary code execution vulnerability was found in LuaTeX (TeX Live) that allows any document compiled with older versions of LuaTeX to execute arbitrary shell commands, even with shell escape disabled.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7texliveAffected
Red Hat Enterprise Linux 8texliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionstexliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.2 Advanced Update SupporttexliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.2 Telecommunications Update ServicetexliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionstexliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupporttexliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicetexliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionstexliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.6 Extended Update SupporttexliveFixedRHSA-2023:366119.06.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=2208943texlive: arbitrary code execution allows document complied with older version

EPSS

Процентиль: 62%
0.00422
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 2 лет назад

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

CVSS3: 7.8
nvd
больше 2 лет назад

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

CVSS3: 7.8
debian
больше 2 лет назад

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when ...

suse-cvrf
больше 2 лет назад

Security update for texlive

suse-cvrf
больше 2 лет назад

Security update for texlive

EPSS

Процентиль: 62%
0.00422
Низкий

7.8 High

CVSS3