Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-39331

Опубликовано: 23 июн. 2024
Источник: debian
EPSS Низкий

Описание

In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
emacsfixed1:29.4+1-1package
org-modefixed9.7.5+dfsg-1package
org-modeignoredbookwormpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2024/06/23/1

  • Fixed by: https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29.4&id=c645e1d8205f0f0663ec4a2d27575b238c646c7c (emacs-29.4)

  • Fixed by: https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=f4cc61636947b5c2f0afc67174dd369fe3277aa8 (release_9.7.5)

EPSS

Процентиль: 75%
0.00903
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
12 месяцев назад

In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.

CVSS3: 7.8
redhat
12 месяцев назад

In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.

CVSS3: 9.8
nvd
12 месяцев назад

In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.

CVSS3: 9.8
msrc
11 месяцев назад

Описание отсутствует

suse-cvrf
11 месяцев назад

Security update for emacs

EPSS

Процентиль: 75%
0.00903
Низкий