mktexlsr revision 22855 through revision 36625 as packaged in texlive allows local users to write to arbitrary files via a symlink attack.
{
"binaries": [
{
"binary_name": "libkpathsea-dev",
"binary_version": "2013.20130729.30972-2ubuntu0.1"
},
{
"binary_name": "libkpathsea6",
"binary_version": "2013.20130729.30972-2ubuntu0.1"
},
{
"binary_name": "libptexenc-dev",
"binary_version": "2013.20130729.30972-2ubuntu0.1"
},
{
"binary_name": "libptexenc1",
"binary_version": "2013.20130729.30972-2ubuntu0.1"
},
{
"binary_name": "texlive-binaries",
"binary_version": "2013.20130729.30972-2ubuntu0.1"
}
],
"availability": "No subscription required"
}