CVE-2017-17513

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-17513
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-17513.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-17513
Related
Published
2017-12-14T16:29:00Z
Modified
2025-01-08T04:36:12.746160Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to linked_scripts/context/stubs/unix/mtxrun, texmf-dist/scripts/context/stubs/mswin/mtxrun.lua, and texmf-dist/tex/luatex/lualibs/lualibs-os.lua.

References

Affected packages

Debian:11 / context

Package

Name
context
Purl
pkg:deb/debian/context?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2020.*

2020.03.10.20200331-1
2020.03.10.20200331-1+deb11u1

2021.*

2021.03.05.20220211-1
2021.03.05.20230120+dfsg-1
2021.03.05.20230120+dfsg-2

2023.*

2023.05.05.20230730+dfsg-1
2023.05.05.20230730+dfsg-2

2024.*

2024.04.01.20240428+dfsg-1
2024.04.01.20240428+dfsg-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / context

Package

Name
context
Purl
pkg:deb/debian/context?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2021.*

2021.03.05.20230120+dfsg-1
2021.03.05.20230120+dfsg-1+deb12u1
2021.03.05.20230120+dfsg-2

2023.*

2023.05.05.20230730+dfsg-1
2023.05.05.20230730+dfsg-2

2024.*

2024.04.01.20240428+dfsg-1
2024.04.01.20240428+dfsg-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / context

Package

Name
context
Purl
pkg:deb/debian/context?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2021.*

2021.03.05.20230120+dfsg-1
2021.03.05.20230120+dfsg-2

2023.*

2023.05.05.20230730+dfsg-1
2023.05.05.20230730+dfsg-2

2024.*

2024.04.01.20240428+dfsg-1
2024.04.01.20240428+dfsg-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:11 / texlive-base

Package

Name
texlive-base
Purl
pkg:deb/debian/texlive-base?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2020.*

2020.20210202-3

2021.*

2021.20210921-1
2021.20211127-1
2021.20211217-1
2021.20220204-1

2022.*

2022.20220405-1
2022.20220405-2
2022.20220605-1
2022.20220722-1
2022.20220923-1
2022.20220923-2
2022.20221123-1
2022.20230122-1
2022.20230122-2
2022.20230122-3

2023.*

2023.20230613-1
2023.20230613-2
2023.20230613-3
2023.20231007-1
2023.20231207-1
2023.20240207-1

2024.*

2024.20240401-1
2024.20240401-2
2024.20240401-3
2024.20240706-1
2024.20240829-1
2024.20240829-2
2024.20241102-1
2024.20241115-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / texlive-base

Package

Name
texlive-base
Purl
pkg:deb/debian/texlive-base?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2022.*

2022.20230122-3

2023.*

2023.20230613-1
2023.20230613-2
2023.20230613-3
2023.20231007-1
2023.20231207-1
2023.20240207-1

2024.*

2024.20240401-1
2024.20240401-2
2024.20240401-3
2024.20240706-1
2024.20240829-1
2024.20240829-2
2024.20241102-1
2024.20241115-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / texlive-base

Package

Name
texlive-base
Purl
pkg:deb/debian/texlive-base?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2022.*

2022.20230122-3

2023.*

2023.20230613-1
2023.20230613-2
2023.20230613-3
2023.20231007-1
2023.20231207-1
2023.20240207-1

2024.*

2024.20240401-1
2024.20240401-2
2024.20240401-3
2024.20240706-1
2024.20240829-1
2024.20240829-2
2024.20241102-1
2024.20241115-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:11 / texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/debian/texlive-bin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2020.*

2020.20200327.54578-7
2020.20200327.54578-7+deb11u1
2020.20200327.54578-7+deb11u2

2021.*

2021.20210626.59705-1

2022.*

2022.20220321.62855-1
2022.20220321.62855-2
2022.20220321.62855-3
2022.20220321.62855-4
2022.20220321.62855-5
2022.20220321.62855-5.1
2022.20220321.62855-6
2022.20220321.62855-7
2022.20220321.62855-8

2023.*

2023.20230311.66589-1
2023.20230311.66589-2
2023.20230311.66589-3
2023.20230311.66589-4
2023.20230311.66589-5
2023.20230311.66589-6
2023.20230311.66589-7
2023.20230311.66589-8
2023.20230311.66589-9

2024.*

2024.20240313.70630+ds-1
2024.20240313.70630+ds-2
2024.20240313.70630+ds-3
2024.20240313.70630+ds-4
2024.20240313.70630+ds-5

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/debian/texlive-bin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2022.*

2022.20220321.62855-5.1
2022.20220321.62855-5.1+deb12u1
2022.20220321.62855-5.1+deb12u2
2022.20220321.62855-6
2022.20220321.62855-7
2022.20220321.62855-8

2023.*

2023.20230311.66589-1
2023.20230311.66589-2
2023.20230311.66589-3
2023.20230311.66589-4
2023.20230311.66589-5
2023.20230311.66589-6
2023.20230311.66589-7
2023.20230311.66589-8
2023.20230311.66589-9

2024.*

2024.20240313.70630+ds-1
2024.20240313.70630+ds-2
2024.20240313.70630+ds-3
2024.20240313.70630+ds-4
2024.20240313.70630+ds-5

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / texlive-bin

Package

Name
texlive-bin
Purl
pkg:deb/debian/texlive-bin?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2022.*

2022.20220321.62855-5.1
2022.20220321.62855-6
2022.20220321.62855-7
2022.20220321.62855-8

2023.*

2023.20230311.66589-1
2023.20230311.66589-2
2023.20230311.66589-3
2023.20230311.66589-4
2023.20230311.66589-5
2023.20230311.66589-6
2023.20230311.66589-7
2023.20230311.66589-8
2023.20230311.66589-9

2024.*

2024.20240313.70630+ds-1
2024.20240313.70630+ds-2
2024.20240313.70630+ds-3
2024.20240313.70630+ds-4
2024.20240313.70630+ds-5

Ecosystem specific

{
    "urgency": "unimportant"
}