Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-14482

Опубликовано: 04 сент. 2017
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).

A command injection flaw within the Emacs "enriched mode" handling has been discovered. By tricking an unsuspecting user into opening a specially crafted file using Emacs, a remote attacker could exploit this flaw to execute arbitrary commands with the privileges of the Emacs user.

Меры по смягчению последствий

This issue can be mitigated by adding the following lines to the Emacs init file (for example ~/.emacs, ~/emacs.d/init.el, site-start.el) and avoiding options that would bypass normal initialization, like 'emacs -Q': ;; Mitigate CVE-2017-14482 in Emacs 25.2 and earlier (require 'enriched) (defun enriched-decode-display-prop (start end &optional param) (list start end))

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5emacsWill not fix
Red Hat Enterprise Linux 6emacsWill not fix
Red Hat Enterprise Linux 7emacsFixedRHSA-2017:277119.09.2017

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1490409emacs: command injection flaw within "enriched mode" handling

EPSS

Процентиль: 89%
0.04583
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 8 лет назад

GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).

CVSS3: 8.8
nvd
около 8 лет назад

GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).

CVSS3: 8.8
debian
около 8 лет назад

GNU Emacs before 25.3 allows remote attackers to execute arbitrary cod ...

suse-cvrf
около 8 лет назад

Security update for emacs

suse-cvrf
около 8 лет назад

Security update for emacs

EPSS

Процентиль: 89%
0.04583
Низкий

8.1 High

CVSS3