CVE-2023-32700

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/05/2023
Last modified:
31/01/2025

Description

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:luatex_project:luatex:*:*:*:*:*:*:*:* 1.04 (including) 1.16.2 (excluding)
cpe:2.3:a:miktex:miktex:*:*:*:*:*:*:*:* 2.9.6300 (including) 23.5 (excluding)
cpe:2.3:a:tug:tex_live:*:*:*:*:*:*:*:* 2017 (including) 2023 (excluding)