跳转到帖子

Rocky Linux: CVE-2023-32700: texlive (RLSA-2023-3661)

recommended_posts

发布于
  • Members

Rocky Linux: CVE-2023-32700: texlive (RLSA-2023-3661)

Severity
7
CVSS
(AV:L/AC:M/Au:N/C:C/I:C/A:C)
Published
05/20/2023
Created
03/07/2024
Added
04/19/2024
Modified
01/28/2025

Description

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

Solution(s)

  • rocky-upgrade-texlive
  • rocky-upgrade-texlive-bibtex
  • rocky-upgrade-texlive-bibtex-debuginfo
  • rocky-upgrade-texlive-debuginfo
  • rocky-upgrade-texlive-debugsource
  • rocky-upgrade-texlive-dvipdfmx
  • rocky-upgrade-texlive-dvipng
  • rocky-upgrade-texlive-dvipng-debuginfo
  • rocky-upgrade-texlive-dvips
  • rocky-upgrade-texlive-dvips-debuginfo
  • rocky-upgrade-texlive-dvisvgm
  • rocky-upgrade-texlive-dvisvgm-debuginfo
  • rocky-upgrade-texlive-fontware
  • rocky-upgrade-texlive-fontware-debuginfo
  • rocky-upgrade-texlive-gsftopk
  • rocky-upgrade-texlive-gsftopk-debuginfo
  • rocky-upgrade-texlive-kpathsea
  • rocky-upgrade-texlive-kpathsea-debuginfo
  • rocky-upgrade-texlive-lib
  • rocky-upgrade-texlive-lib-debuginfo
  • rocky-upgrade-texlive-lib-devel
  • rocky-upgrade-texlive-luahbtex
  • rocky-upgrade-texlive-luahbtex-debuginfo
  • rocky-upgrade-texlive-luatex
  • rocky-upgrade-texlive-luatex-debuginfo
  • rocky-upgrade-texlive-makeindex
  • rocky-upgrade-texlive-makeindex-debuginfo
  • rocky-upgrade-texlive-metafont
  • rocky-upgrade-texlive-metafont-debuginfo
  • rocky-upgrade-texlive-metapost
  • rocky-upgrade-texlive-metapost-debuginfo
  • rocky-upgrade-texlive-mfware
  • rocky-upgrade-texlive-mfware-debuginfo
  • rocky-upgrade-texlive-pdftex
  • rocky-upgrade-texlive-pdftex-debuginfo
  • rocky-upgrade-texlive-tex
  • rocky-upgrade-texlive-tex-debuginfo
  • rocky-upgrade-texlive-tex4ht
  • rocky-upgrade-texlive-tex4ht-debuginfo
  • rocky-upgrade-texlive-xdvi
  • rocky-upgrade-texlive-xdvi-debuginfo
  • rocky-upgrade-texlive-xetex
  • rocky-upgrade-texlive-xetex-debuginfo

References

  • https://attackerkb.com/topics/cve-2023-32700
  • CVE - 2023-32700
  • https://errata.rockylinux.org/RLSA-2023:3661
  • 查看数 703
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…