PT-2023-9170 · Luatex+4 · Luatex+4

Max Chernoff

·

Published

2023-05-11

·

Updated

2026-01-29

·

CVE-2023-32668

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions LuaTeX versions prior to 1.17.0 TeX Live versions prior to 2023 r66984 MiKTeX versions prior to 23.5
Description The issue allows a document, compiled with default settings, to make arbitrary network requests due to full access to the socket library being permitted by default. This is stated in the documentation and can be exploited by a remote attacker to execute arbitrary commands. No information is provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For LuaTeX versions prior to 1.17.0, update to version 1.17.0 or later to resolve the issue. For TeX Live versions prior to 2023 r66984, update to version 2023 r66984 or later to resolve the issue. For MiKTeX versions prior to 23.5, update to version 23.5 or later to resolve the issue. As a temporary workaround, consider disabling the socket library until a patch is available. Restrict access to the socket library to minimize the risk of exploitation.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-04366
CVE-2023-32668
DLA-3941-1
MGASA-2024-0108
OPENSUSE-SU-2024:12936-1
USN-6695-1
USN-7985-1

Affected Products

Linuxmint
Luatex
Miktex
Tex Live
Ubuntu