Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-32700

Опубликовано: 20 мая 2023
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

An arbitrary code execution vulnerability was found in LuaTeX (TeX Live) that allows any document compiled with older versions of LuaTeX to execute arbitrary shell commands, even with shell escape disabled.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7texliveAffected
Red Hat Enterprise Linux 8texliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionstexliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.2 Advanced Update SupporttexliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.2 Telecommunications Update ServicetexliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionstexliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupporttexliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.4 Telecommunications Update ServicetexliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionstexliveFixedRHSA-2023:366119.06.2023
Red Hat Enterprise Linux 8.6 Extended Update SupporttexliveFixedRHSA-2023:366119.06.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=2208943texlive: arbitrary code execution allows document complied with older version

EPSS

Процентиль: 48%
0.00246
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 лет назад

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

CVSS3: 7.8
nvd
около 2 лет назад

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

CVSS3: 7.8
debian
около 2 лет назад

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when ...

suse-cvrf
около 2 лет назад

Security update for texlive

suse-cvrf
около 2 лет назад

Security update for texlive

EPSS

Процентиль: 48%
0.00246
Низкий

7.8 High

CVSS3