Описание
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.
A flaw was found in the Emacs package. If a file name or directory name contains shell metacharacters, arbitrary code may be executed.
Отчет
This vulnerability is only triggered when a local user introduces untrusted input, via a file or directory with a crafted name. For this reason, this flaw has been rated with a Moderate security impact.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | emacs | Out of support scope | ||
Red Hat Enterprise Linux 7 | emacs | Fixed | RHSA-2023:3481 | 06.06.2023 |
Red Hat Enterprise Linux 8 | emacs | Fixed | RHSA-2023:7083 | 14.11.2023 |
Red Hat Enterprise Linux 8 | emacs | Fixed | RHSA-2023:7083 | 14.11.2023 |
Red Hat Enterprise Linux 8.6 Extended Update Support | emacs | Fixed | RHSA-2024:1103 | 05.03.2024 |
Red Hat Enterprise Linux 8.8 Extended Update Support | emacs | Fixed | RHSA-2024:1408 | 19.03.2024 |
Red Hat Enterprise Linux 9 | emacs | Fixed | RHSA-2023:2626 | 09.05.2023 |
Показывать по
Дополнительная информация
Статус:
7.8 High
CVSS3
Связанные уязвимости
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has ...
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.
7.8 High
CVSS3