Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-1244

Опубликовано: 12 фев. 2025
Источник: debian
EPSS Низкий

Описание

A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
emacsfixed1:30.1+1-1package

Примечания

  • https://debbugs.gnu.org/66390

  • Fixed by: https://git.savannah.gnu.org/cgit/emacs.git/commit/?id=820f0793f0b46448928905552726c1f1b999062f

  • https://emacsninja.com/posts/cve-2025-1244-from-emacs-url-handler-to-rce.html

EPSS

Процентиль: 38%
0.00165
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
6 месяцев назад

A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.

CVSS3: 8.8
redhat
6 месяцев назад

A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.

CVSS3: 8.8
nvd
6 месяцев назад

A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.

CVSS3: 8.8
msrc
6 месяцев назад

Описание отсутствует

suse-cvrf
6 месяцев назад

Security update for emacs

EPSS

Процентиль: 38%
0.00165
Низкий