Логотип exploitDog
bind: "CVE-2022-48338"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2022-48338"

Количество 10

Количество 10

ubuntu логотип

CVE-2022-48338

больше 2 лет назад

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.

CVSS3: 7.3
EPSS: Низкий
redhat логотип

CVE-2022-48338

больше 2 лет назад

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2022-48338

больше 2 лет назад

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.

CVSS3: 7.3
EPSS: Низкий
msrc логотип

CVE-2022-48338

больше 2 лет назад

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2022-48338

больше 2 лет назад

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, th ...

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-hm6m-2xg8-mc5q

больше 2 лет назад

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2024-06035

больше 2 лет назад

Уязвимость функции ruby-find-library-file текстового редактора EMACS, связанная с неправильной нейтрализацией специальных элементов, используемых в команде, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0598-1

больше 2 лет назад

Security update for emacs

EPSS: Низкий
redos логотип

ROS-20240806-06

11 месяцев назад

Множественные уязвимости emacs

CVSS3: 9.8
EPSS: Низкий
oracle-oval логотип

ELSA-2023-2626

около 2 лет назад

ELSA-2023-2626: emacs security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-48338

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-48338

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-48338

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 7.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-48338

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, th ...

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-hm6m-2xg8-mc5q

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-06035

Уязвимость функции ruby-find-library-file текстового редактора EMACS, связанная с неправильной нейтрализацией специальных элементов, используемых в команде, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.3
0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:0598-1

Security update for emacs

больше 2 лет назад
redos логотип
ROS-20240806-06

Множественные уязвимости emacs

CVSS3: 9.8
11 месяцев назад
oracle-oval логотип
ELSA-2023-2626

ELSA-2023-2626: emacs security update (IMPORTANT)

около 2 лет назад

Уязвимостей на страницу