Luatex Project
luatex_project
2 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Luatex Project MiktexTug3Luatex MiktexTex LiveJan 31, 2025 May 20, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects...Show more |
3Luatex Project MiktexTug3Luatex MiktexTex LiveNov 3, 2025 May 11, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted by default, as stated in the documentatio...Show more |