USN-6115-1

Source
https://ubuntu.com/security/notices/USN-6115-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6115-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-6115-1
Related
Published
2023-05-30T09:11:23.516725Z
Modified
2023-05-30T09:11:23.516725Z
Summary
texlive-bin vulnerability
Details

Max Chernoff discovered that LuaTeX (TeX Live) did not properly disable shell escape. An attacker could possibly use this issue to execute arbitrary shell commands.

References

Affected packages

Ubuntu:18.04:LTS / texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/ubuntu/texlive-bin?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2017.20170613.44572-8ubuntu0.2

Affected versions

2017.*

2017.20170613.44572-5build1
2017.20170613.44572-5build2
2017.20170613.44572-6
2017.20170613.44572-6build1
2017.20170613.44572-6ubuntu1
2017.20170613.44572-8build1
2017.20170613.44572-8ubuntu0.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libkpathsea-dev"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libkpathsea6"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libkpathsea6-dbgsym"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libptexenc-dev"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libptexenc1"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libptexenc1-dbgsym"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libsynctex-dev"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libsynctex1"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libsynctex1-dbgsym"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libtexlua52"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libtexlua52-dbgsym"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libtexlua52-dev"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libtexluajit-dev"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libtexluajit2"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "libtexluajit2-dbgsym"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "texlive-binaries"
        },
        {
            "binary_version": "2017.20170613.44572-8ubuntu0.2",
            "binary_name": "texlive-binaries-dbgsym"
        }
    ]
}

Ubuntu:20.04:LTS / texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/ubuntu/texlive-bin?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2019.20190605.51237-3ubuntu0.1

Affected versions

2019.*

2019.20190605.51237-2build1
2019.20190605.51237-3
2019.20190605.51237-3build1
2019.20190605.51237-3build2

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libkpathsea-dev"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libkpathsea6"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libkpathsea6-dbgsym"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libptexenc-dev"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libptexenc1"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libptexenc1-dbgsym"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libsynctex-dev"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libsynctex2"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libsynctex2-dbgsym"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libtexlua53"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libtexlua53-dbgsym"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libtexlua53-dev"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libtexluajit-dev"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libtexluajit2"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "libtexluajit2-dbgsym"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "texlive-binaries"
        },
        {
            "binary_version": "2019.20190605.51237-3ubuntu0.1",
            "binary_name": "texlive-binaries-dbgsym"
        }
    ]
}

Ubuntu:22.04:LTS / texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/ubuntu/texlive-bin?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2021.20210626.59705-1ubuntu0.1

Affected versions

2020.*

2020.20200327.54578-7
2020.20200327.54578-7build1

2021.*

2021.20210626.59705-1
2021.20210626.59705-1build1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libkpathsea-dev"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libkpathsea6"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libkpathsea6-dbgsym"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libptexenc-dev"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libptexenc1"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libptexenc1-dbgsym"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libsynctex-dev"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libsynctex2"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libsynctex2-dbgsym"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libtexlua53"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libtexlua53-dbgsym"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libtexlua53-dev"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libtexluajit-dev"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libtexluajit2"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "libtexluajit2-dbgsym"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "texlive-binaries"
        },
        {
            "binary_version": "2021.20210626.59705-1ubuntu0.1",
            "binary_name": "texlive-binaries-dbgsym"
        }
    ]
}