[Git][security-tracker-team/security-tracker][master] Add CVE-2023-32668/texlive-bin for luatex

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu May 11 19:56:19 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a2ffa365 by Salvatore Bonaccorso at 2023-05-11T20:55:30+02:00
Add CVE-2023-32668/texlive-bin for luatex

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9,7 +9,8 @@ CVE-2023-2454 [CREATE SCHEMA ... schema_element defeats protective search_path c
 	- postgresql-11 <removed>
 	NOTE: https://www.postgresql.org/about/news/postgresql-153-148-1311-1215-and-1120-released-2637/
 CVE-2023-32668 (LuaTeX before 1.17.0 enables the socket library by default.)
-	TODO: check
+	- texlive-bin <unfixed>
+	NOTE: https://tug.org/pipermail/tex-live/2023-May/049188.html
 CVE-2023-32080 (Wings is the server control plane for Pterodactyl Panel. A vulnerabili ...)
 	NOT-FOR-US: Pterodactyl panel
 CVE-2023-31477 (A path traversal issue was discovered on GL.iNet devices before 3.216. ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a2ffa365fbdc1ce45bcdfc10294b42b6891f4c95

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a2ffa365fbdc1ce45bcdfc10294b42b6891f4c95
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230511/4924bf2b/attachment.htm>


More information about the debian-security-tracker-commits mailing list