Описание
ELSA-2017-2771: emacs security update (IMPORTANT)
[1:24.3-20]
- fix unsafe enriched mode translations (#1490452)
Обновленные пакеты
Oracle Linux 7
Oracle Linux aarch64
emacs
24.3-20.el7_4
emacs-common
24.3-20.el7_4
emacs-el
24.3-20.el7_4
emacs-filesystem
24.3-20.el7_4
emacs-nox
24.3-20.el7_4
emacs-terminal
24.3-20.el7_4
Oracle Linux x86_64
emacs
24.3-20.el7_4
emacs-common
24.3-20.el7_4
emacs-el
24.3-20.el7_4
emacs-filesystem
24.3-20.el7_4
emacs-nox
24.3-20.el7_4
emacs-terminal
24.3-20.el7_4
Связанные CVE
Связанные уязвимости
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).
GNU Emacs before 25.3 allows remote attackers to execute arbitrary cod ...