Mageia 2023-0233: texlive security update
Summary
Any document compiled with older versions of LuaTeX can execute arbitrary
shell commands, even with shell escape disabled. (CVE-2023-32700)
References
- https://bugs.mageia.org/show_bug.cgi?id=31952
- https://www.debian.org/security/2023/dsa-5406
- https://www.maxchernoff.ca/p/luatex-vulnerabilities
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-32700
Resolution
MGASA-2023-0233 - Updated texlive packages fix security vulnerability
SRPMS
- 8/core/texlive-20200406-9.1.mga8