Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-27986

Опубликовано: 08 мар. 2023
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.

A flaw was found in the Emacs text editor. A crafted mailto URI, when opened with emacsclient-mail.desktop, can result in Emacs Lisp code injection.

Отчет

The emacsclient-mail.desktop file is not distributed in Red Hat Enterprise Linux 6, 7, 8 and 9. Therefore, Red Hat Enterprise Linux is not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6emacsNot affected
Red Hat Enterprise Linux 7emacsNot affected
Red Hat Enterprise Linux 8emacsNot affected
Red Hat Enterprise Linux 9emacsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-77
https://bugzilla.redhat.com/show_bug.cgi?id=2176473emacs: Emacs Lisp code injection via a crafted mailto URI

EPSS

Процентиль: 20%
0.00065
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 3 года назад

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.

CVSS3: 7.8
nvd
почти 3 года назад

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.

CVSS3: 7.8
msrc
почти 3 года назад

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.

CVSS3: 7.8
debian
почти 3 года назад

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to E ...

CVSS3: 9.8
github
почти 3 года назад

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters.

EPSS

Процентиль: 20%
0.00065
Низкий

7.8 High

CVSS3