{"id":"DEBIAN-CVE-2017-17513","details":"TeX Live through 20170524 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, related to linked_scripts/context/stubs/unix/mtxrun, texmf-dist/scripts/context/stubs/mswin/mtxrun.lua, and texmf-dist/tex/luatex/lualibs/lualibs-os.lua.","modified":"2026-09-01T20:03:46.436601334Z","published":"2017-12-14T16:29:00.293Z","upstream":["CVE-2017-17513"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2017-17513"}],"affected":[{"package":{"name":"context","ecosystem":"Debian:12","purl":"pkg:deb/debian/context?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2021.03.05.20230120+dfsg-1","2021.03.05.20230120+dfsg-1+deb12u1","2021.03.05.20230120+dfsg-2","2023.05.05.20230730+dfsg-1","2023.05.05.20230730+dfsg-2","2024.04.01.20240428+dfsg-1","2024.04.01.20240428+dfsg-2","2025.03.05.20250324+dfsg-1","2025.03.05.20250324+dfsg-2","2025.03.05.20250324+dfsg-3","2025.09.21.20251026+dfsg-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-17513.json"}},{"package":{"name":"context","ecosystem":"Debian:13","purl":"pkg:deb/debian/context?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2024.04.01.20240428+dfsg-2","2025.03.05.20250324+dfsg-1","2025.03.05.20250324+dfsg-2","2025.03.05.20250324+dfsg-3","2025.09.21.20251026+dfsg-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-17513.json"}},{"package":{"name":"context","ecosystem":"Debian:14","purl":"pkg:deb/debian/context?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2024.04.01.20240428+dfsg-2","2025.03.05.20250324+dfsg-1","2025.03.05.20250324+dfsg-2","2025.03.05.20250324+dfsg-3","2025.09.21.20251026+dfsg-1"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-17513.json"}},{"package":{"name":"texlive-base","ecosystem":"Debian:12","purl":"pkg:deb/debian/texlive-base?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2022.20230122-3","2023.20230613-1","2023.20230613-2","2023.20230613-3","2023.20231007-1","2023.20231207-1","2023.20240207-1","2024.20240401-1","2024.20240401-2","2024.20240401-3","2024.20240706-1","2024.20240829-1","2024.20240829-2","2024.20241102-1","2024.20241115-1","2024.20250114-1","2024.20250309-1","2025.20250727-1","2025.20250727-2","2025.20250727-3","2025.20250927-1","2025.20250927-2","2025.20250927-3","2025.20250927-4","2025.20251127-1","2025.20260124-1","2026.20260328-1","2026.20260328-2","2026.20260328-3","2026.20260328-4","2026.20260527-1","2026.20260527-2","2026.20260527-3","2026.20260711-1","2026.20260711-2"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-17513.json"}},{"package":{"name":"texlive-base","ecosystem":"Debian:13","purl":"pkg:deb/debian/texlive-base?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2024.20250309-1","2025.20250727-1","2025.20250727-2","2025.20250727-3","2025.20250927-1","2025.20250927-2","2025.20250927-3","2025.20250927-4","2025.20251127-1","2025.20260124-1","2026.20260328-1","2026.20260328-2","2026.20260328-3","2026.20260328-4","2026.20260527-1","2026.20260527-2","2026.20260527-3","2026.20260711-1","2026.20260711-2"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-17513.json"}},{"package":{"name":"texlive-base","ecosystem":"Debian:14","purl":"pkg:deb/debian/texlive-base?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2024.20250309-1","2025.20250727-1","2025.20250727-2","2025.20250727-3","2025.20250927-1","2025.20250927-2","2025.20250927-3","2025.20250927-4","2025.20251127-1","2025.20260124-1","2026.20260328-1","2026.20260328-2","2026.20260328-3","2026.20260328-4","2026.20260527-1","2026.20260527-2","2026.20260527-3","2026.20260711-1","2026.20260711-2"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-17513.json"}},{"package":{"name":"texlive-bin","ecosystem":"Debian:12","purl":"pkg:deb/debian/texlive-bin?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2022.20220321.62855-5.1","2022.20220321.62855-5.1+deb12u1","2022.20220321.62855-5.1+deb12u2","2022.20220321.62855-6","2022.20220321.62855-7","2022.20220321.62855-8","2023.20230311.66589-1","2023.20230311.66589-2","2023.20230311.66589-3","2023.20230311.66589-4","2023.20230311.66589-5","2023.20230311.66589-6","2023.20230311.66589-7","2023.20230311.66589-8","2023.20230311.66589-9","2024.20240313.70630+ds-1","2024.20240313.70630+ds-2","2024.20240313.70630+ds-3","2024.20240313.70630+ds-4","2024.20240313.70630+ds-5","2024.20240313.70630+ds-6","2025.20250727.75242+ds-1","2025.20250727.75242+ds-2","2025.20250727.75242+ds-3","2025.20250727.75242+ds-4","2025.20250727.75242+ds-5","2025.20250727.75242+ds-5~hurd.1","2026.20260303.78225+ds-1","2026.20260303.78225+ds-2","2026.20260303.78225+ds-3","2026.20260303.78225+ds-4","2026.20260303.78225+ds-5"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-17513.json"}},{"package":{"name":"texlive-bin","ecosystem":"Debian:13","purl":"pkg:deb/debian/texlive-bin?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2024.20240313.70630+ds-6","2025.20250727.75242+ds-1","2025.20250727.75242+ds-2","2025.20250727.75242+ds-3","2025.20250727.75242+ds-4","2025.20250727.75242+ds-5","2025.20250727.75242+ds-5~hurd.1","2026.20260303.78225+ds-1","2026.20260303.78225+ds-2","2026.20260303.78225+ds-3","2026.20260303.78225+ds-4","2026.20260303.78225+ds-5"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-17513.json"}},{"package":{"name":"texlive-bin","ecosystem":"Debian:14","purl":"pkg:deb/debian/texlive-bin?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2024.20240313.70630+ds-6","2025.20250727.75242+ds-1","2025.20250727.75242+ds-2","2025.20250727.75242+ds-3","2025.20250727.75242+ds-4","2025.20250727.75242+ds-5","2025.20250727.75242+ds-5~hurd.1","2026.20260303.78225+ds-1","2026.20260303.78225+ds-2","2026.20260303.78225+ds-3","2026.20260303.78225+ds-4","2026.20260303.78225+ds-5"],"ecosystem_specific":{"urgency":"unimportant"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2017-17513.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}