Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-30204

Опубликовано: 25 мар. 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.

A flaw was found in Emacs. When Emacs is used as an email client, a preview of a crafted LaTeX document attached to an email can exhaust the disk space or the inodes allocated for the partition where the /tmp directory is located. This issue possibly results in a denial of service.

Меры по смягчению последствий

Do not open or do not generate a preview of LaTeX documents from untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10emacsAffected
Red Hat Enterprise Linux 6emacsOut of support scope
Red Hat Enterprise Linux 7emacsOut of support scope
Red Hat Enterprise Linux 8emacsAffected
Red Hat Enterprise Linux 9emacsFixedRHSA-2024:930212.11.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-349
https://bugzilla.redhat.com/show_bug.cgi?id=2280297emacs: LaTeX preview is enabled by default for e-mail attachments

EPSS

Процентиль: 4%
0.00017
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 2.8
ubuntu
около 2 лет назад

In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.

CVSS3: 2.8
nvd
около 2 лет назад

In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.

CVSS3: 2.8
msrc
7 месяцев назад

In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.

CVSS3: 2.8
debian
около 2 лет назад

In Emacs before 29.3, LaTeX preview is enabled by default for e-mail a ...

CVSS3: 2.8
github
около 2 лет назад

In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.

EPSS

Процентиль: 4%
0.00017
Низкий

5.5 Medium

CVSS3