Bug 1268144 - luatex suspected to be subject to CVE-2014-5461
Summary: luatex suspected to be subject to CVE-2014-5461
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: texlive
Version: rawhide
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Tom "spot" Callaway
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-10-01 22:37 UTC by Ralf Corsepius
Modified: 2015-10-02 02:48 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-10-02 02:48:10 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Ralf Corsepius 2015-10-01 22:37:02 UTC
Description of problem:

During today's (2015-10-01) FPC meeting, the version of lua bundled with texlive was identified to be potentially subject to CVE-2014-5461 [1].

[1] http://www.cvedetails.com/cve/CVE-2014-5461/

Comment 1 Tom "spot" Callaway 2015-10-02 02:48:10 UTC
Not vulnerable. Texlive 2014 (oldest in current Fedora) ships with lua 5.2.3, which has this patched.


Note You need to log in before you can comment on or make changes to this bug.