LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.
References
Configurations
Configuration 1 (hide)
|
History
31 Jan 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-77 |
Information
Published : 2023-05-20 18:15
Updated : 2025-01-31 16:15
NVD link : CVE-2023-32700
Mitre link : CVE-2023-32700
CVE.ORG link : CVE-2023-32700
JSON object : View
Products Affected
tug
- tex_live
luatex_project
- luatex
miktex
- miktex
CWE
NVD-CWE-Other
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')