Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2017-2771

Опубликовано: 19 сент. 2017
Источник: oracle-oval
Платформа: Oracle Linux 7

Описание

ELSA-2017-2771: emacs security update (IMPORTANT)

[1:24.3-20]

  • fix unsafe enriched mode translations (#1490452)

Обновленные пакеты

Oracle Linux 7

Oracle Linux aarch64

emacs

24.3-20.el7_4

emacs-common

24.3-20.el7_4

emacs-el

24.3-20.el7_4

emacs-filesystem

24.3-20.el7_4

emacs-nox

24.3-20.el7_4

emacs-terminal

24.3-20.el7_4

Oracle Linux x86_64

emacs

24.3-20.el7_4

emacs-common

24.3-20.el7_4

emacs-el

24.3-20.el7_4

emacs-filesystem

24.3-20.el7_4

emacs-nox

24.3-20.el7_4

emacs-terminal

24.3-20.el7_4

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 8 лет назад

GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).

CVSS3: 8.1
redhat
около 8 лет назад

GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).

CVSS3: 8.8
nvd
около 8 лет назад

GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).

CVSS3: 8.8
debian
около 8 лет назад

GNU Emacs before 25.3 allows remote attackers to execute arbitrary cod ...

suse-cvrf
около 8 лет назад

Security update for emacs