Описание
A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosure.
Отчет
This Moderate impact vulnerability in Emacs affects Red Hat Enterprise Linux 8, 9, and 10. The flaw, an off-by-one heap buffer overflow and uninitialized read, occurs when processing specially crafted SVG CSS. Exploitation requires a user to open a malicious SVG CSS file with Emacs.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | emacs | Under investigation | ||
| Red Hat Enterprise Linux 6 | emacs | Under investigation | ||
| Red Hat Enterprise Linux 7 | emacs | Under investigation | ||
| Red Hat Enterprise Linux 8 | emacs | Under investigation | ||
| Red Hat Enterprise Linux 9 | emacs | Under investigation |
Показывать по
Дополнительная информация
Статус:
6.1 Medium
CVSS3
Связанные уязвимости
A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosure.
A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially crafted SVG (Scalable Vector Graphics) CSS (Cascading Style Sheets) data. A local user could exploit this by convincing a victim to open a malicious SVG file, which may lead to a denial of service (DoS) or potentially information disclosure.
Emacs: emacs: memory corruption vulnerability when processing svg css
A flaw was found in GNU Emacs. This vulnerability, a memory corruption ...
6.1 Medium
CVSS3