Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-48337

Опубликовано: 21 фев. 2023
Источник: redhat
CVSS3: 7.3

Описание

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command (suggested in the etags documentation) in a situation where the current working directory has contents that depend on untrusted input.

A flaw was found in the Emacs package. This flaw allows attackers to execute commands via shell metacharacters in the name of a source-code file.

Отчет

This vulnerability is only triggered when a local user introduces untrusted input, via a file with a crafted name. For this reason, this flaw has been rated with a Moderate security impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6emacsOut of support scope
Red Hat Enterprise Linux 7emacsWill not fix
Red Hat Enterprise Linux 8emacsFixedRHSA-2023:708314.11.2023
Red Hat Enterprise Linux 8emacsFixedRHSA-2023:708314.11.2023
Red Hat Enterprise Linux 8.6 Extended Update SupportemacsFixedRHSA-2024:110305.03.2024
Red Hat Enterprise Linux 8.8 Extended Update SupportemacsFixedRHSA-2024:140819.03.2024
Red Hat Enterprise Linux 9emacsFixedRHSA-2023:262609.05.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=2171987emacs: command execution via shell metacharacters

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 2 лет назад

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command (suggested in the etags documentation) in a situation where the current working directory has contents that depend on untrusted input.

CVSS3: 9.8
nvd
больше 2 лет назад

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command (suggested in the etags documentation) in a situation where the current working directory has contents that depend on untrusted input.

CVSS3: 9.8
msrc
больше 2 лет назад

Описание отсутствует

CVSS3: 9.8
debian
больше 2 лет назад

GNU Emacs through 28.2 allows attackers to execute commands via shell ...

CVSS3: 9.8
github
больше 2 лет назад

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command (suggested in the etags documentation) in a situation where the current working directory has contents that depend on untrusted input.

7.3 High

CVSS3

Уязвимость CVE-2022-48337