--------------------------------------------------------------------------------Fedora Update Notification
FEDORA-2023-38094d905c
2023-05-31 01:34:55.988933
--------------------------------------------------------------------------------Name        : texlive-base
Product     : Fedora 38
Version     : 20220321
Release     : 72.fc38
URL         : https://tug.org/texlive/
Summary     : TeX formatting system
Description :
The TeX Live software distribution offers a complete TeX system for a
variety of Unix, Macintosh, Windows and other platforms. It
encompasses programs for editing, typesetting, previewing and printing
of TeX documents in many different languages, and a large collection
of TeX macros and font libraries.

The distribution includes extensive general documentation about TeX,
as well as the documentation for the included software packages.

--------------------------------------------------------------------------------Update Information:

Fixes CVE-2023-32700. Also fixes issues with mptopdf.pl, thumb2pdf.pl, and
mtxrun.
--------------------------------------------------------------------------------ChangeLog:

* Thu May 25 2023 Tom Callaway  - 10:20220321-72
- apply upstream fix for CVE-2023-32700
- patch texmfcnf.lua
- fix mptopdf.pl and thumbpdf.pl to have proper interpreter lines
--------------------------------------------------------------------------------References:

  [ 1 ] Bug #2208943 - CVE-2023-32700 texlive: arbitrary code execution allows document complied with older version
        https://bugzilla.redhat.com/show_bug.cgi?id=2208943
--------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2023-38094d905c' at the command
line. For more information, refer to the dnf documentation available at
https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
--------------------------------------------------------------------------------_______________________________________________
package-announce mailing list -- package-announce@lists.fedoraproject.org
To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/
Do not reply to spam, report it: https://pagure.io/login/

Fedora 38: texlive-base 2023-38094d905c

May 31, 2023
Fixes CVE-2023-32700

Summary

The TeX Live software distribution offers a complete TeX system for a

variety of Unix, Macintosh, Windows and other platforms. It

encompasses programs for editing, typesetting, previewing and printing

of TeX documents in many different languages, and a large collection

of TeX macros and font libraries.

The distribution includes extensive general documentation about TeX,

as well as the documentation for the included software packages.

Fixes CVE-2023-32700. Also fixes issues with mptopdf.pl, thumb2pdf.pl, and

mtxrun.

* Thu May 25 2023 Tom Callaway - 10:20220321-72

- apply upstream fix for CVE-2023-32700

- patch texmfcnf.lua

- fix mptopdf.pl and thumbpdf.pl to have proper interpreter lines

[ 1 ] Bug #2208943 - CVE-2023-32700 texlive: arbitrary code execution allows document complied with older version

https://bugzilla.redhat.com/show_bug.cgi?id=2208943

su -c 'dnf upgrade --advisory FEDORA-2023-38094d905c' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Do not reply to spam, report it: https://pagure.io/login/

FEDORA-2023-38094d905c 2023-05-31 01:34:55.988933 Product : Fedora 38 Version : 20220321 Release : 72.fc38 URL : https://tug.org/texlive/ Summary : TeX formatting system Description : The TeX Live software distribution offers a complete TeX system for a variety of Unix, Macintosh, Windows and other platforms. It encompasses programs for editing, typesetting, previewing and printing of TeX documents in many different languages, and a large collection of TeX macros and font libraries. The distribution includes extensive general documentation about TeX, as well as the documentation for the included software packages. Fixes CVE-2023-32700. Also fixes issues with mptopdf.pl, thumb2pdf.pl, and mtxrun. * Thu May 25 2023 Tom Callaway - 10:20220321-72 - apply upstream fix for CVE-2023-32700 - patch texmfcnf.lua - fix mptopdf.pl and thumbpdf.pl to have proper interpreter lines [ 1 ] Bug #2208943 - CVE-2023-32700 texlive: arbitrary code execution allows document complied with older version https://bugzilla.redhat.com/show_bug.cgi?id=2208943 su -c 'dnf upgrade --advisory FEDORA-2023-38094d905c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/ Do not reply to spam, report it: https://pagure.io/login/

Change Log

References

Update Instructions

Severity
Product : Fedora 38
Version : 20220321
Release : 72.fc38
URL : https://tug.org/texlive/
Summary : TeX formatting system

Related News