DEBIAN-CVE-2023-46048

Source
https://security-tracker.debian.org/tracker/CVE-2023-46048
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-46048.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2023-46048
Upstream
Published
2024-03-27T05:15:47.560Z
Modified
2026-03-17T02:44:05.786384Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c. NOTE: this is disputed because it should be categorized as a usability problem.

References

Affected packages

Debian:11 / texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/debian/texlive-bin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2020.*
2020.20200327.54578-7
2020.20200327.54578-7+deb11u1
2020.20200327.54578-7+deb11u2
2021.*
2021.20210626.59705-1
2022.*
2022.20220321.62855-1
2022.20220321.62855-2
2022.20220321.62855-3
2022.20220321.62855-4
2022.20220321.62855-5
2022.20220321.62855-5.1
2022.20220321.62855-6
2022.20220321.62855-7
2022.20220321.62855-8
2023.*
2023.20230311.66589-1
2023.20230311.66589-2
2023.20230311.66589-3
2023.20230311.66589-4
2023.20230311.66589-5
2023.20230311.66589-6
2023.20230311.66589-7
2023.20230311.66589-8
2023.20230311.66589-9
2024.*
2024.20240313.70630+ds-1
2024.20240313.70630+ds-2
2024.20240313.70630+ds-3
2024.20240313.70630+ds-4
2024.20240313.70630+ds-5
2024.20240313.70630+ds-6
2025.*
2025.20250727.75242+ds-1
2025.20250727.75242+ds-2
2025.20250727.75242+ds-3
2025.20250727.75242+ds-4
2025.20250727.75242+ds-5~hurd.1
2025.20250727.75242+ds-5

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-46048.json"

Debian:12 / texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/debian/texlive-bin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2022.*
2022.20220321.62855-5.1
2022.20220321.62855-5.1+deb12u1
2022.20220321.62855-5.1+deb12u2
2022.20220321.62855-6
2022.20220321.62855-7
2022.20220321.62855-8
2023.*
2023.20230311.66589-1
2023.20230311.66589-2
2023.20230311.66589-3
2023.20230311.66589-4
2023.20230311.66589-5
2023.20230311.66589-6
2023.20230311.66589-7
2023.20230311.66589-8
2023.20230311.66589-9
2024.*
2024.20240313.70630+ds-1
2024.20240313.70630+ds-2
2024.20240313.70630+ds-3
2024.20240313.70630+ds-4
2024.20240313.70630+ds-5
2024.20240313.70630+ds-6
2025.*
2025.20250727.75242+ds-1
2025.20250727.75242+ds-2
2025.20250727.75242+ds-3
2025.20250727.75242+ds-4
2025.20250727.75242+ds-5~hurd.1
2025.20250727.75242+ds-5

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-46048.json"

Debian:13 / texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/debian/texlive-bin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2024.*
2024.20240313.70630+ds-6
2025.*
2025.20250727.75242+ds-1
2025.20250727.75242+ds-2
2025.20250727.75242+ds-3
2025.20250727.75242+ds-4
2025.20250727.75242+ds-5~hurd.1
2025.20250727.75242+ds-5

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-46048.json"

Debian:14 / texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/debian/texlive-bin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2024.*
2024.20240313.70630+ds-6
2025.*
2025.20250727.75242+ds-1
2025.20250727.75242+ds-2
2025.20250727.75242+ds-3
2025.20250727.75242+ds-4
2025.20250727.75242+ds-5~hurd.1
2025.20250727.75242+ds-5

Ecosystem specific

{
    "urgency": "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-46048.json"