Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2023:3661

Опубликовано: 24 июн. 2023
Источник: rocky
Оценка: Important

Описание

Important: texlive security update

The texlive packages contain TeXLive, an implementation of TeX for Linux or UNIX systems.

Security Fix(es):

  • texlive: arbitrary code execution allows document complied with older version (CVE-2023-32700)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

  • Rocky Linux 9

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 2 лет назад

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

CVSS3: 7.8
redhat
около 2 лет назад

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

CVSS3: 7.8
nvd
около 2 лет назад

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

CVSS3: 7.8
debian
около 2 лет назад

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when ...

suse-cvrf
около 2 лет назад

Security update for texlive