Headline
CVE-2023-32668: source/texk/web2c/luatexdir/ChangeLog · b266ef076c96b382cd23a4c93204e247bb98626a · TeXLive / luatex · GitLab
LuaTeX before 1.17.0 enables the socket library by default.
To find the state of this project’s repository at the time of any of these versions, check out the tags.
Related news
Ubuntu Security Notice 6695-1 - It was discovered that TeX Live incorrectly handled certain memory operations in the embedded axodraw2 tool. An attacker could possibly use this issue to cause TeX Live to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS. It was discovered that TeX Live allowed documents to make arbitrary network requests. If a user or automated system were tricked into opening a specially crafted document, a remote attacker could possibly use this issue to exfiltrate sensitive information, or perform other network-related attacks. This issue only affected Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.