VDB
GCVE-VVD-MAGEIA-2017-127
GCVE-VVD-MAGEIA-2017-127
Advisory Published
It was discovered that texlive whitelists mpost as an external program
to be run from within the TeX source code (called \write18). Since
mpost allows to specify other programs to be run, an attacker can take
advantage of this flaw for arbitrary code execution when compiling a TeX
document (CVE-2016-10243).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | ghostscript | 0 (affected), 9.22-1.1.mga5 (unaffected) | — |
| Mageia | ghostscript | 0 (affected), 9.22-1.1.mga6 (unaffected) | — |
| Mageia | texlive | 0 (affected), 20130530-21.1.mga5 (unaffected), 0 (affected), 20130530-21.1.mga5 (unaffected) | — |
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.