5.5 CVE-2023-32668

Patch Exploit
 

LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted by default, as stated in the documentation. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.
https://nvd.nist.gov/vuln/detail/CVE-2023-32668

Categories

CWE-NVD-noinfo

References


 

CPE

cpe start end
Configuration 1
cpe:2.3:a:luatex_project:luatex:*:*:*:*:*:*:*:* >= 0.27.0 < 1.17.0
cpe:2.3:a:miktex:miktex:*:*:*:*:*:*:*:* >= 2.9.0 < 23.5
cpe:2.3:a:tug:tex_live:*:*:*:*:*:*:*:* >= 2009 < 2023


REMEDIATION


Patch

Url
https://gitlab.lisn.upsaclay.fr/texlive/luatex/-/tags/1.17.0
https://gitlab.lisn.upsaclay.fr/texlive/luatex/-/tags/1.17.0


EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url

Other Nist (github, ...)

Url
https://tug.org/~mseven/luatex.html#luasocket
https://tug.org/~mseven/luatex.html#luasocket


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry