texlive[70064] branches/branch2023.final/Master: tl-update-auto

commits+karl at tug.org commits+karl at tug.org
Thu Feb 22 03:23:47 CET 2024


Revision: 70064
          https://tug.org/svn/texlive?view=revision&revision=70064
Author:   karl
Date:     2024-02-22 03:23:47 +0100 (Thu, 22 Feb 2024)
Log Message:
-----------
tl-update-auto

Modified Paths:
--------------
    branches/branch2023.final/Master/texmf-dist/bibtex/bib/beebe/typeset.bib
    branches/branch2023.final/Master/tlpkg/installer/ctan-mirrors.pl

Modified: branches/branch2023.final/Master/texmf-dist/bibtex/bib/beebe/typeset.bib
===================================================================
--- branches/branch2023.final/Master/texmf-dist/bibtex/bib/beebe/typeset.bib	2024-02-22 02:21:14 UTC (rev 70063)
+++ branches/branch2023.final/Master/texmf-dist/bibtex/bib/beebe/typeset.bib	2024-02-22 02:23:47 UTC (rev 70064)
@@ -2,9 +2,9 @@
 %%% ====================================================================
 %%%  BibTeX-file{
 %%%     author          = "Nelson H. F. Beebe",
-%%%     version         = "2.81",
-%%%     date            = "08 November 2023",
-%%%     time            = "07:21:30 MST",
+%%%     version         = "2.82",
+%%%     date            = "20 February 2024",
+%%%     time            = "13:05:20 MST",
 %%%     filename        = "typeset.bib",
 %%%     address         = "University of Utah
 %%%                        Department of Mathematics, 110 LCB
@@ -14,7 +14,7 @@
 %%%     telephone       = "+1 801 581 5254",
 %%%     FAX             = "+1 801 581 4148",
 %%%     URL             = "https://www.math.utah.edu/~beebe",
-%%%     checksum        = "61010 26601 127656 1200459",
+%%%     checksum        = "15050 26689 128064 1204316",
 %%%     email           = "beebe at math.utah.edu, beebe at acm.org,
 %%%                        beebe at computer.org (Internet)",
 %%%     codetable       = "ISO/ASCII",
@@ -39,7 +39,7 @@
 %%%                        and PDF (Portable Document Format), and
 %%%                        sgml.bib covers SGML and HTML.
 %%%
-%%%                        At version 2.81, the year coverage looked
+%%%                        At version 2.82, the year coverage looked
 %%%                        like this:
 %%%
 %%%                             1881 (   1)    1929 (   1)    1977 (  12)
@@ -72,9 +72,9 @@
 %%%                             1908 (   0)    1956 (   0)    2004 (   3)
 %%%                             1909 (   0)    1957 (   0)    2005 (   7)
 %%%                             1910 (   0)    1958 (   2)    2006 (   3)
-%%%                             1911 (   0)    1959 (   1)    2007 (   3)
+%%%                             1911 (   0)    1959 (   1)    2007 (   4)
 %%%                             1913 (   0)    1961 (   2)    2009 (   2)
-%%%                             1914 (   0)    1962 (   3)    2010 (   2)
+%%%                             1914 (   0)    1962 (   3)    2010 (   4)
 %%%                             1915 (   0)    1963 (   2)    2011 (   3)
 %%%                             1916 (   1)    1964 (   6)    2012 (   5)
 %%%                             1917 (   0)    1965 (  10)    2013 (   7)
@@ -85,7 +85,7 @@
 %%%                             1922 (   0)    1970 (   8)    2018 (   3)
 %%%                             1923 (   1)    1971 (  11)    2019 (   7)
 %%%                             1924 (   0)    1972 (   9)    2020 (   1)
-%%%                             1925 (   0)    1973 (  12)    2021 (   2)
+%%%                             1925 (   0)    1973 (  12)    2021 (   3)
 %%%                             1926 (   1)    1974 (   8)    2022 (   2)
 %%%                             1927 (   0)    1975 (  15)    2023 (   1)
 %%%                             1928 (   1)    1976 (   8)
@@ -92,19 +92,19 @@
 %%%                             19xx (   3)
 %%%                             20xx (   2)
 %%%
-%%%                             Article:        348
+%%%                             Article:        350
 %%%                             Book:           327
 %%%                             InCollection:     5
-%%%                             InProceedings:   55
+%%%                             InProceedings:   56
 %%%                             Manual:          42
 %%%                             MastersThesis:   21
-%%%                             Misc:            19
+%%%                             Misc:            20
 %%%                             Periodical:       8
 %%%                             PhdThesis:        6
 %%%                             Proceedings:     33
 %%%                             TechReport:      38
 %%%
-%%%                             Total entries:  902
+%%%                             Total entries:  906
 %%%
 %%%                        This bibliography has been collected from
 %%%                        bibliographies in the author's personal
@@ -383,6 +383,8 @@
 
 @String{j-LIB-HI-TECH           = "Library Hi Tech"}
 
+ at String{j-LOGIN                 = ";login: the USENIX Association newsletter"}
+
 @String{j-MICROCOMPUT-INF-MANAGE = "Microcomputers for Information Management"}
 
 @String{j-MICROPROC-MICROPROG   = "Microprocessing and Microprogramming"}
@@ -24074,6 +24076,19 @@
                  invented.",
 }
 
+ at Misc{Anonymous:2007:KPL,
+  author =       "Anonymous",
+  title =        "{Knuth \& Plass line}-breaking Revisited",
+  howpublished = "Web site",
+  day =          "23",
+  month =        jul,
+  year =         "2007",
+  bibdate =      "Fri Jan 19 13:19:53 2024",
+  bibsource =    "https://www.math.utah.edu/pub/tex/bib/typeset.bib",
+  URL =          "https://defoe.sourceforge.net/folio/knuth-plass.html",
+  acknowledgement = ack-nhfb,
+}
+
 @TechReport{ICNS:2007:UIR,
   author =       "{Interdivisional Committee on Nomenclature and
                  Symbols}",
@@ -24221,6 +24236,39 @@
                  etc; printing",
 }
 
+ at Article{Checkoway:2010:DTL,
+  author =       "Stephen Checkoway and Hovav Shacham and Eric
+                 Rescorla",
+  title =        "Don't take {\LaTeX} files from strangers",
+  journal =      j-LOGIN,
+  volume =       "35",
+  number =       "1",
+  pages =        "17--22",
+  month =        aug,
+  year =         "2010",
+  bibdate =      "Tue Feb 20 13:08:28 2024",
+  bibsource =    "https://www.math.utah.edu/pub/tex/bib/typeset.bib",
+  URL =          "https://www.usenix.org/system/files/login/articles/73506-checkoway.pdf",
+  acknowledgement = ack-nhfb,
+}
+
+ at InProceedings{Checkoway:2010:TOD,
+  author =       "Stephen Checkoway and Hovav Shacham and Eric
+                 Rescorla",
+  editor =       "????",
+  booktitle =    "{3rd USENIX Workshop on Large-Scale Exploits and
+                 Emergent Threats, LEET '10}",
+  title =        "Are Text-Only Data Formats Safe? {Or}, Use This
+                 {\LaTeX} Class File to Pwn Your Computer.",
+  publisher =    pub-USENIX,
+  address =      pub-USENIX:adr,
+  pages =        "??--??",
+  year =         "2010",
+  bibdate =      "Tue Feb 20 13:02:38 2024",
+  bibsource =    "https://www.math.utah.edu/pub/tex/bib/typeset.bib",
+  acknowledgement = ack-nhfb,
+}
+
 @Book{Kelly:2010:ABT,
   author =       "Jerry Kelly",
   title =        "The art of the book in the twentieth century: a study
@@ -25560,6 +25608,46 @@
   keywords =     "Adobe Systems co-founder",
 }
 
+ at Article{Lacombe:2021:CYA,
+  author =       "Guilhem Lacombe and Kseniia Masalygina and Anass
+                 Tahiri and Carole Adam and C{\'e}dric Lauradoux",
+  title =        "Can You Accept {\LaTeX} Files from Strangers? {Ten}
+                 Years Later",
+  journal =      "arXiv.org",
+  volume =       "??",
+  number =       "??",
+  pages =        "1--10",
+  day =          "1",
+  month =        feb,
+  year =         "2021",
+  bibdate =      "Tue Feb 20 12:57:24 2024",
+  bibsource =    "https://www.math.utah.edu/pub/tex/bib/typeset.bib",
+  URL =          "https://arxiv.org/abs/2102.00856",
+  abstract =     "It is well-known that Microsoft Word\slash Excel
+                 compatible documents or PDF files can contain malicious
+                 content. \LaTeX{} files are unfortunately no exception
+                 either. \LaTeX{} users often include third-party codes
+                 through sources or packages ({\tt .sty} or {\tt .cls}
+                 files). But those packages can execute malicious
+                 commands on the users' system, in order to capture
+                 sensitive information or to perform denial of service
+                 attacks. Checkoway et al. [3] were the first to warn
+                 \LaTeX{} users of these threats. Collaborative
+                 cloud-based \LaTeX{} editors and services compiling
+                 \LaTeX{} sources are particularly concerned. In this
+                 paper, we have created a \LaTeX{} package that collects
+                 system data and hides them inside the PDF file produced
+                 by the target. Then, we have measured what can be
+                 recovered by hackers using a malicious \LaTeX{} file on
+                 online services, and which measures those services have
+                 enforced to thwart the threats. Services defend
+                 themselves using sandbox or commands restrictions.
+                 Commands restrictions are more difficult to setup and
+                 we found one service (PMLatex) which is too
+                 permissive",
+  acknowledgement = ack-nhfb,
+}
+
 @Article{Thomas:2021:TLT,
   author =       "Edd Thomas",
   title =        "Turning Letters into Tones: A century ago, the

Modified: branches/branch2023.final/Master/tlpkg/installer/ctan-mirrors.pl
===================================================================
--- branches/branch2023.final/Master/tlpkg/installer/ctan-mirrors.pl	2024-02-22 02:21:14 UTC (rev 70063)
+++ branches/branch2023.final/Master/tlpkg/installer/ctan-mirrors.pl	2024-02-22 02:23:47 UTC (rev 70064)
@@ -17,9 +17,11 @@
       'https://mirrors.cqu.edu.cn/CTAN/' => 1,
       'https://mirrors.jlu.edu.cn/CTAN/' => 1,
       'https://mirrors.nju.edu.cn/CTAN/' => 1,
+      'https://mirrors.pku.edu.cn/ctan/' => 1,
       'https://mirrors.sjtug.sjtu.edu.cn/ctan/' => 1,
       'https://mirrors.sustech.edu.cn/CTAN/' => 1,
       'https://mirrors.tuna.tsinghua.edu.cn/CTAN/' => 1,
+      'https://mirrors.ustc.edu.cn/CTAN/' => 1,
     },
     'Hong Kong' => {
       'https://mirror-hk.koddos.net/CTAN/' => 1,



More information about the tex-live-commits mailing list.