Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:1915

Опубликовано: 07 мая 2025
Источник: rocky
Оценка: Important

Описание

Important: emacs security update

GNU Emacs is a powerful, customizable, self-documenting text editor. It provides special code editing features, a scripting language (elisp), and the capability to read e-mail and news.

Security Fix(es):

  • emacs: Shell Injection Vulnerability in GNU Emacs via Custom "man" URI Scheme (CVE-2025-1244)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
emacsx86_6411.el9_5.1emacs-27.2-11.el9_5.1.x86_64.rpm
emacs-commonx86_6411.el9_5.1emacs-common-27.2-11.el9_5.1.x86_64.rpm
emacs-filesystemnoarch11.el9_5.1emacs-filesystem-27.2-11.el9_5.1.noarch.rpm
emacs-lucidx86_6411.el9_5.1emacs-lucid-27.2-11.el9_5.1.x86_64.rpm
emacs-noxx86_6411.el9_5.1emacs-nox-27.2-11.el9_5.1.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 8.8
ubuntu
9 месяцев назад

A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.

CVSS3: 8.8
redhat
9 месяцев назад

A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.

CVSS3: 8.8
nvd
9 месяцев назад

A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.

CVSS3: 8.8
msrc
9 месяцев назад

Emacs: shell injection vulnerability in gnu emacs via custom "man" uri scheme

CVSS3: 8.8
debian
9 месяцев назад

A command injection flaw was found in the text editor Emacs. It could ...