Vulnerability Bulletins

DSA-3803 texlive-base - security update

   
Affected software Debian
 
It was discovered that texlive-base, the TeX Live package which providesthe essential TeX programs and files, whitelists mpost as an externalprogram to be run from within the TeX source code (called write18).Since mpost allows to specify other programs to be run, an attacker cantake advantage of this flaw for arbitrary code execution when compilinga TeX document.

More info:

https://www.debian.org/security/2017/dsa-3803