CVE-2016-10243: texlive: mpost allows to run non-whitelisted external programs

Severity: Critical

CVSS Score: 9.8

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.