[Tex/LaTex] Full version of TeX Live: malware checked

Securitytexlive

I am wondering if texlive-full is bearing any security issues? Why everybody does trust it? Are they checked by anybody?

Thanks for helping and educating me on this point 🙂

Best Answer

TeX Live consists of a relatively small number of executable items and a large number of 'other things', principally LaTeX packages, fonts and documentation (PDF files). The standard settings for the binary part of the set up are 'cautious' about potential security risks in the (La)TeX parts of the system, but these are likely to be more theoretical than actual. To the best of my knowledge there has not been an attempt to send to CTAN, and thus to TeX Live, a LaTeX package which deliberately tries to use \write18 to cause trouble. The number of people who would be affected is very small, and it's extremely unlikely that a self-replicating approach would be successful. The binary parts of the system are of course of more interest in this regard, but again there are not to my knowledge any actual issues (though see Is luatex as secure as pdftex? for discussion on the affect of Lua scripting on security).

All of that said, there is no-one checking each CTAN upload for security fixes, and the TeX Live team take most of their material more-or-less directly from CTAN. As such, if you are looking for some form of 'assurance' on the code then you will have to find a downstream group doing the work. That I know of, Ubuntu do not do this, although you might be better asking on an Ubunut-specific site about that. Perhaps other operating system teams (most obviously OpenBSD) might do such work if they are very security-focussed, but again that is more about those systems than about TeX.