<?xml version="1.0" encoding="utf-8"?>
  <?xml-stylesheet type="text/xsl" href="sa-render.xsl"?>
  <update from="huaweicloud.com" type="security" status="stable" version="1">
    <id>HCE3-SA-2025-0162</id>
    <title>An update for texlive-base is now available for HCE 3.0</title>
    <severity>Important</severity>
    <release>HCE 3.0</release>
    <issued date="2025-10-09 06:38:21"/>
    <updated date="2025-10-09 06:38:21"/>
    <references>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2023-46051" id="CVE-2023-46051" title="CVE-2023-46051 Base Score: 3.3 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2023-32700" id="CVE-2023-32700" title="CVE-2023-32700 Base Score: 7.8 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" type="cve"/>
      <reference href="https://nvd.nist.gov/vuln/detail/CVE-2023-46048" id="CVE-2023-46048" title="CVE-2023-46048 Base Score: 6.2 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" type="cve"/>
    </references>
    <description>Security Fix(es):

TeX Live 944e257 allows a NULL pointer dereference in texk/web2c/pdftexdir/tounicode.c. NOTE: this is disputed because it should be categorized as a usability problem. (CVE-2023-46051)

LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5. (CVE-2023-32700)

Tex Live 944e257 has a NULL pointer dereference in texk/web2c/pdftexdir/writet1.c. NOTE: this is disputed because it should be categorized as a usability problem. (CVE-2023-46048)
</description>
    <pkglist>
      <collection short="HCE 3.0" package="texlive-base">
        <name>HCE 3.0</name>
        <package arch="x86_64" name="texlive-base" version="20210325" release="9.hce3">
          <filename>texlive-base-20210325-9.hce3.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="texlive-bibtex" version="20210325" release="9.hce3">
          <filename>texlive-bibtex-20210325-9.hce3.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="texlive-dvipdfmx" version="20210325" release="9.hce3">
          <filename>texlive-dvipdfmx-20210325-9.hce3.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="texlive-dvips" version="20210325" release="9.hce3">
          <filename>texlive-dvips-20210325-9.hce3.x86_64.rpm</filename>
        </package>
        <package arch="noarch" name="texlive-epstopdf" version="20210325" release="9.hce3">
          <filename>texlive-epstopdf-20210325-9.hce3.noarch.rpm</filename>
        </package>
        <package arch="noarch" name="texlive-glyphlist" version="20210325" release="9.hce3">
          <filename>texlive-glyphlist-20210325-9.hce3.noarch.rpm</filename>
        </package>
        <package arch="x86_64" name="texlive-gsftopk" version="20210325" release="9.hce3">
          <filename>texlive-gsftopk-20210325-9.hce3.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="texlive-kpathsea" version="20210325" release="9.hce3">
          <filename>texlive-kpathsea-20210325-9.hce3.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="texlive-lib" version="20210325" release="9.hce3">
          <filename>texlive-lib-20210325-9.hce3.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="texlive-luatex" version="20210325" release="9.hce3">
          <filename>texlive-luatex-20210325-9.hce3.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="texlive-makeindex" version="20210325" release="9.hce3">
          <filename>texlive-makeindex-20210325-9.hce3.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="texlive-metafont" version="20210325" release="9.hce3">
          <filename>texlive-metafont-20210325-9.hce3.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="texlive-mfware" version="20210325" release="9.hce3">
          <filename>texlive-mfware-20210325-9.hce3.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="texlive-pdftex" version="20210325" release="9.hce3">
          <filename>texlive-pdftex-20210325-9.hce3.x86_64.rpm</filename>
        </package>
        <package arch="noarch" name="texlive-texlive.infra" version="20210325" release="9.hce3">
          <filename>texlive-texlive.infra-20210325-9.hce3.noarch.rpm</filename>
        </package>
        <package arch="noarch" name="texlive-texlive-en" version="20210325" release="9.hce3">
          <filename>texlive-texlive-en-20210325-9.hce3.noarch.rpm</filename>
        </package>
        <package arch="noarch" name="texlive-texlive-scripts" version="20210325" release="9.hce3">
          <filename>texlive-texlive-scripts-20210325-9.hce3.noarch.rpm</filename>
        </package>
        <package arch="x86_64" name="texlive-tex" version="20210325" release="9.hce3">
          <filename>texlive-tex-20210325-9.hce3.x86_64.rpm</filename>
        </package>
        <package arch="x86_64" name="texlive-xdvi" version="20210325" release="9.hce3">
          <filename>texlive-xdvi-20210325-9.hce3.x86_64.rpm</filename>
        </package>
        <package arch="aarch64" name="texlive-base" version="20210325" release="9.hce3">
          <filename>texlive-base-20210325-9.hce3.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="texlive-bibtex" version="20210325" release="9.hce3">
          <filename>texlive-bibtex-20210325-9.hce3.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="texlive-dvipdfmx" version="20210325" release="9.hce3">
          <filename>texlive-dvipdfmx-20210325-9.hce3.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="texlive-dvips" version="20210325" release="9.hce3">
          <filename>texlive-dvips-20210325-9.hce3.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="texlive-gsftopk" version="20210325" release="9.hce3">
          <filename>texlive-gsftopk-20210325-9.hce3.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="texlive-kpathsea" version="20210325" release="9.hce3">
          <filename>texlive-kpathsea-20210325-9.hce3.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="texlive-lib" version="20210325" release="9.hce3">
          <filename>texlive-lib-20210325-9.hce3.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="texlive-luatex" version="20210325" release="9.hce3">
          <filename>texlive-luatex-20210325-9.hce3.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="texlive-makeindex" version="20210325" release="9.hce3">
          <filename>texlive-makeindex-20210325-9.hce3.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="texlive-metafont" version="20210325" release="9.hce3">
          <filename>texlive-metafont-20210325-9.hce3.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="texlive-mfware" version="20210325" release="9.hce3">
          <filename>texlive-mfware-20210325-9.hce3.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="texlive-pdftex" version="20210325" release="9.hce3">
          <filename>texlive-pdftex-20210325-9.hce3.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="texlive-tex" version="20210325" release="9.hce3">
          <filename>texlive-tex-20210325-9.hce3.aarch64.rpm</filename>
        </package>
        <package arch="aarch64" name="texlive-xdvi" version="20210325" release="9.hce3">
          <filename>texlive-xdvi-20210325-9.hce3.aarch64.rpm</filename>
        </package>
      </collection>
    </pkglist>
  </update>
