CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
Percentile
27.0%
LuaTeX before 1.17.0 allows a document (compiled with the default settings)
to make arbitrary network requests. This occurs because full access to the
socket library is permitted by default, as stated in the documentation.
This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 18.04 | noarch | texlive-bin | < any | UNKNOWN |
ubuntu | 20.04 | noarch | texlive-bin | < 2019.20190605.51237-3ubuntu0.2 | UNKNOWN |
ubuntu | 22.04 | noarch | texlive-bin | < 2021.20210626.59705-1ubuntu0.2 | UNKNOWN |
ubuntu | 16.04 | noarch | texlive-bin | < any | UNKNOWN |
gitlab.lisn.upsaclay.fr/texlive/luatex/-/blob/b266ef076c96b382cd23a4c93204e247bb98626a/source/texk/web2c/luatexdir/ChangeLog#L1-L3
gitlab.lisn.upsaclay.fr/texlive/luatex/-/tags/1.17.0
launchpad.net/bugs/cve/CVE-2023-32668
nvd.nist.gov/vuln/detail/CVE-2023-32668
security-tracker.debian.org/tracker/CVE-2023-32668
tug.org/pipermail/tex-live/2023-May/049188.html
ubuntu.com/security/notices/USN-6695-1
www.cve.org/CVERecord?id=CVE-2023-32668