Name | CVE-2023-32668 |
Description | LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted by default, as stated in the documentation. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
References | DLA-3941-1, ELA-1225-1 |
Debian Bugs | 1036470 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
texlive-bin (PTS) | jessie, jessie (lts) | 2014.20140926.35254-6+deb8u1 | vulnerable |
stretch (security) | 2016.20160513.41080.dfsg-2+deb9u1 | vulnerable | |
stretch (lts), stretch | 2016.20160513.41080.dfsg-2+deb9u2 | fixed | |
buster, buster (lts) | 2018.20181218.49446-1+deb10u3 | fixed | |
buster (security) | 2018.20181218.49446-1+deb10u2 | vulnerable | |
bullseye | 2020.20200327.54578-7+deb11u1 | vulnerable | |
bullseye (security) | 2020.20200327.54578-7+deb11u2 | fixed | |
bookworm | 2022.20220321.62855-5.1+deb12u1 | fixed | |
sid, trixie | 2024.20240313.70630+ds-5 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
texlive-bin | source | stretch | 2016.20160513.41080.dfsg-2+deb9u2 | ELA-1225-1 | ||
texlive-bin | source | buster | 2018.20181218.49446-1+deb10u3 | ELA-1225-1 | ||
texlive-bin | source | bullseye | 2020.20200327.54578-7+deb11u2 | DLA-3941-1 | ||
texlive-bin | source | bookworm | 2022.20220321.62855-5.1+deb12u1 | |||
texlive-bin | source | (unstable) | 2022.20220321.62855-6 | 1036470 |
[buster] - texlive-bin <no-dsa> (Minor issue)
https://tug.org/pipermail/tex-live/2023-May/049188.html
https://gitlab.lisn.upsaclay.fr/texlive/luatex/-/commit/b266ef076c96b382cd23a4c93204e247bb98626a
https://gitlab.lisn.upsaclay.fr/texlive/luatex/-/commit/e7df9234420973a2f69aac1b10cbb5f00b0cda4d
https://gitlab.lisn.upsaclay.fr/texlive/luatex/-/commit/da4492c789e25f05255d54e45447d3da79098967
https://www.maxchernoff.ca/p/luatex-vulnerabilities#luasocket
[jessie] - texlive-bin <no-dsa> (Minor issue)