Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-30205

Опубликовано: 25 мар. 2024
Источник: redhat
CVSS3: 7.8

Описание

In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.

A flaw was found in Emacs. Org mode considers the content of remote files, such as files opened with TRAMP on remote systems, to be trusted, resulting in arbitrary code execution.

Отчет

To exploit this flaw, an attacker needs to trick a user into opening a crafted Org mode file from a remote system. For this reason, this flaw has been rated with a Moderate security impact.

Меры по смягчению последствий

Do not open untrusted Org mode files from a remote system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10emacsAffected
Red Hat Enterprise Linux 6emacsOut of support scope
Red Hat Enterprise Linux 7emacsOut of support scope
Red Hat Enterprise Linux 8emacsFixedRHSA-2024:698724.09.2024
Red Hat Enterprise Linux 8emacsFixedRHSA-2024:698724.09.2024
Red Hat Enterprise Linux 9emacsFixedRHSA-2024:930212.11.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-349
https://bugzilla.redhat.com/show_bug.cgi?id=2280298emacs: Org mode considers contents of remote files to be trusted

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 2 лет назад

In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.

CVSS3: 7.1
nvd
около 2 лет назад

In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.

CVSS3: 7.1
msrc
почти 2 года назад

In Emacs before 29.3 Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.

CVSS3: 7.1
debian
около 2 лет назад

In Emacs before 29.3, Org mode considers contents of remote files to b ...

CVSS3: 7.1
github
около 2 лет назад

In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.

7.8 High

CVSS3