Описание
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters.
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the function org-babel-execute:latex in ob-latex.el can result in arbitrary command execution.
Меры по смягчению последствий
Do not evaluate untrusted Lisp or org-mode code.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | emacs | Not affected | ||
Red Hat Enterprise Linux 7 | emacs | Not affected | ||
Red Hat Enterprise Linux 8 | emacs | Fixed | RHSA-2023:1930 | 24.04.2023 |
Red Hat Enterprise Linux 8 | emacs | Fixed | RHSA-2023:1930 | 24.04.2023 |
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | emacs | Fixed | RHSA-2023:3189 | 17.05.2023 |
Red Hat Enterprise Linux 8.2 Advanced Update Support | emacs | Fixed | RHSA-2023:1915 | 20.04.2023 |
Red Hat Enterprise Linux 8.2 Telecommunications Update Service | emacs | Fixed | RHSA-2023:1915 | 20.04.2023 |
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | emacs | Fixed | RHSA-2023:1915 | 20.04.2023 |
Red Hat Enterprise Linux 8.4 Extended Update Support | emacs | Fixed | RHSA-2023:1958 | 25.04.2023 |
Red Hat Enterprise Linux 8.6 Extended Update Support | emacs | Fixed | RHSA-2023:1931 | 24.04.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
Связанные уязвимости
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters.
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters.
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for G ...
EPSS
7.8 High
CVSS3