Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-27985

Опубликовано: 08 мар. 2023
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90

A flaw was found in the Emacs text editor. When opened with emacsclient-mail.desktop, a crafted mailto URI can result in shell command injection due to lack of compliance with the Desktop Entry Specification.

Отчет

The emacsclient-mail.desktop file is not distributed in Red Hat Enterprise Linux 6, 7, 8 and 9. Therefore, Red Hat Enterprise Linux is not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6emacsNot affected
Red Hat Enterprise Linux 7emacsNot affected
Red Hat Enterprise Linux 8emacsNot affected
Red Hat Enterprise Linux 9emacsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=2176823emacs: Shell command injection via a crafted mailto URI

EPSS

Процентиль: 14%
0.00046
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 3 года назад

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90

CVSS3: 7.8
nvd
почти 3 года назад

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90

CVSS3: 7.8
msrc
почти 3 года назад

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90

CVSS3: 7.8
debian
почти 3 года назад

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to s ...

CVSS3: 9.8
github
почти 3 года назад

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification.

EPSS

Процентиль: 14%
0.00046
Низкий

7.8 High

CVSS3