Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LuaTeX 安全漏洞
Vulnerability Description
LuaTeX是LuaTeX公司的pdfTeX 的扩展版本,使用 Lua 作为嵌入式脚本语言。 LuaTeX 1.17.0之前版本存在安全漏洞,该漏洞源于在编译从不受信任来源获得的TeX文件时允许执行任意shell命令。
CVSS Information
N/A
Vulnerability Type
N/A