Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian 11: DSA-5406-1 Critical: Texlive-bin Shell Command Execution

debian
Calendar Grey May 20, 2023
Debian Logo
An issue has been flagged in texlive-bin by Max Chernoff, which permits unrestricted command execution through LuaTeX. Please ensure you update immediately.
Max Chernoff discovered that improperly secured shell-escape in LuaTeX may result in arbitrary shell command execution, even with shell escape disabled, if specially crafted tex fi...

Summary

For the stable distribution (bullseye), this problem has been fixed in
version 2020.20200327.54578-7+deb11u1.

We recommend that you upgrade your texlive-bin packages.

For the detailed security status of texlive-bin please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/source-package/texlive-bin

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: texlive-bin
CVE ID: CVE-2023-32700

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here