TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shellescapecommands in the texmf.cnf config file.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-base" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-fonts-recommended" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-fonts-recommended-doc" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-full" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-generic-recommended" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-latex-base" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-latex-base-doc" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-latex-recommended" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-latex-recommended-doc" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-luatex" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-metapost" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-metapost-doc" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-omega" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-pictures" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-pictures-doc" }, { "binary_version": "2013.20140215-1ubuntu0.1", "binary_name": "texlive-xetex" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "luasseq" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-base" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-fonts-recommended" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-fonts-recommended-doc" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-full" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-generic-recommended" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-latex-base" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-latex-base-doc" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-latex-recommended" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-latex-recommended-doc" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-luatex" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-metapost" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-metapost-doc" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-omega" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-pictures" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-pictures-doc" }, { "binary_version": "2015.20160320-1ubuntu0.1", "binary_name": "texlive-xetex" } ] }