← Vulnerability feed

Vulnerability record · CVE-2017-17513 · published 14 December 2017

CVE-2017-17513: Tug tex live injection vulnerability

Tug · Tex Live

TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to linked_scripts/context/stubs/unix/mtxrun, texmf-dist/scripts/context/stubs/mswin/mtxrun.lua, and texmf-dist/tex/luatex/lualibs/lualibs-os.lua.

8.8 CVSS 3.0 High EPSS 1.3% · top 31.1% CWE-74 · Injection
8.8CVSS 3.0 base score, v2 6.8
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to linked_scripts/context/stubs/unix/mtxrun, texmf-dist/scripts/context/stubs/mswin/mtxrun.lua, and texmf-dist/tex/luatex/lualibs/lualibs-os.lua.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-17513 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-10243Debian linux improper input validation vulnerabilityTeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.EPSS 7.1%7.8CVE-2023-32700Luatex project luatex command injection vulnerabilityLuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because lu…EPSS 0.80%7.8CVE-2018-17407Tug tex live memory buffer overflow vulnerabilityAn issue was discovered in t1_check_unusual_charstring functions in writet1.c files in TeX Live before 2018-09-21. A buffer overflow in the handling …EPSS 2.1%6.8CVE-2010-0827Tug tex live vulnerabilityInteger overflow in dvips in TeX Live 2009 and earlier, and teTeX, allows remote attackers to cause a denial of service (application crash) or possib…EPSS 4.4%6.8CVE-2010-1440Tug tetex vulnerabilityMultiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of servic…EPSS 3.4%6.8CVE-2010-0739Tug tetex vulnerabilityInteger overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to exe…EPSS 4.9%5.5CVE-2023-32668Luatex project luatex vulnerabilityLuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to th…EPSS 0.37%10.0CVE-2025-20337Cisco ISE API input validation flaw allows unauthenticated root RCECisco ISE and ISE-PIC fail to properly validate user-supplied input in a specific API, letting an unauthenticated remote attacker execute arbitrary c…KEVEPSS 68%analysed

Source: NIST National Vulnerability Database (record CVE-2017-17513), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.