CVE-2023-32668Project Luatex vulnerability

8 documents5 sources
Severity
5.5MEDIUMNVD
OSV9.8OSV7.8
EPSS
0.1%
top 82.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 11
Latest updateJan 29

Description

LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted by default, as stated in the documentation. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDtug/tex_live20092023
NVDmiktex/miktex2.9.023.5
debiandebian/texlive-bin< texlive-bin 2022.20220321.62855-5.1+deb12u1 (bookworm)
NVDluatex_project/luatex0.27.01.17.0

Patches

🔴Vulnerability Details

4
OSV
texlive-bin vulnerabilities2026-01-29
OSV
texlive-bin vulnerabilities2024-03-14
GHSA
GHSA-hm67-jh95-48xh: LuaTeX before 12023-05-11
OSV
CVE-2023-32668: LuaTeX before 12023-05-11

📋Vendor Advisories

3
Ubuntu
TeX Live vulnerabilities2026-01-29
Ubuntu
TeX Live vulnerabilities2024-03-14
Debian
CVE-2023-32668: texlive-bin - LuaTeX before 1.17.0 allows a document (compiled with the default settings) to m...2023