Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-30202

Опубликовано: 25 мар. 2024
Источник: redhat
CVSS3: 7.8

Описание

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.

A flaw was found in Emacs. Arbitrary Lisp code can be evaluated when an Org mode file is opened or when the Org mode is being enabled, resulting in arbitrary code execution.

Отчет

The Emacs package, as shipped in Red Hat Enterprise Linux 8 and 9, is not affected by this vulnerability because the vulnerable code was introduced in a newer version of Emacs. To exploit this flaw, an attacker needs to trick a user into opening a crafted Org mode file. For this reason, this flaw has been rated with a Moderate security impact.

Меры по смягчению последствий

Do not open Org mode files from untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10emacsAffected
Red Hat Enterprise Linux 6emacsOut of support scope
Red Hat Enterprise Linux 7emacsOut of support scope
Red Hat Enterprise Linux 8emacsNot affected
Red Hat Enterprise Linux 9emacsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-95
https://bugzilla.redhat.com/show_bug.cgi?id=2280295emacs: arbitrary Lisp code is evaluated as part of turning on Org mode

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 2 года назад

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.

CVSS3: 7.8
nvd
почти 2 года назад

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.

CVSS3: 7.8
msrc
около 1 года назад

Описание отсутствует

CVSS3: 7.8
debian
почти 2 года назад

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turn ...

CVSS3: 7.8
github
почти 2 года назад

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.

7.8 High

CVSS3

Уязвимость CVE-2024-30202