Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwxq-f9vm-725g

Опубликовано: 21 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.

EPSS

Процентиль: 26%
0.00091
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1116
CWE-116
CWE-77

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 3 года назад

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.

CVSS3: 7.8
redhat
почти 3 года назад

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.

CVSS3: 7.8
nvd
почти 3 года назад

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.

CVSS3: 7.8
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 7.8
debian
почти 3 года назад

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has ...

EPSS

Процентиль: 26%
0.00091
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-1116
CWE-116
CWE-77