CVE-2017-17513
ADVISORY - nistSummary
TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to linked_scripts/context/stubs/unix/mtxrun, texmf-dist/scripts/context/stubs/mswin/mtxrun.lua, and texmf-dist/tex/luatex/lualibs/lualibs-os.lua.
EPSS Score: 0.00508 (0.657)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
ADVISORY - redhat
Improper Input Validation
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in