An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade emacs-filesystemUpgrade emacs-lucidUpgrade emacs-noxUpgrade emacsUpgrade emacs-common | May 15, 2023 | Feb 20, 2023 |
| Amazon Linux Ami 2 | — | Upgrade emacs-noxUpgrade emacs-terminalUpgrade emacsUpgrade emacs-lucidUpgrade emacs-filesystemUpgrade emacs-debuginfoUpgrade emacs-commonUpgrade emacs-devel | Mar 7, 2023 | Feb 20, 2023 |
| Amazon_linux_2023 | — | Upgrade emacs-commonUpgrade emacs-lucidUpgrade emacs-debuginfoUpgrade emacs-noxUpgrade emacs-debugsourceUpgrade emacs-terminalUpgrade emacs-lucid-debuginfoUpgrade emacs-common-debuginfoUpgrade emacs-filesystemUpgrade emacsUpgrade emacs-develUpgrade emacs-nox-debuginfo | Feb 17, 2025 | Feb 21, 2023 |
| Centos_linux | — | Upgrade emacs-lucid-debuginfoUpgrade emacs-common-debuginfoUpgrade emacs-lucidUpgrade emacs-nox-debuginfoUpgrade emacs-filesystemUpgrade emacsUpgrade emacs-commonUpgrade emacs-debuginfoUpgrade emacs-noxUpgrade emacs-debugsource | May 15, 2023 | Feb 20, 2023 |
| Debian | — | Upgrade emacs | Feb 27, 2023 | Feb 20, 2023 |
| Freebsd | — | Upgrade emacs-devel-noxUpgrade emacs-noxUpgrade emacs-develUpgrade emacs-cannaUpgrade emacs | Feb 28, 2023 | Feb 27, 2023 |
| Gentoo Linux | — | Upgrade app-editors/emacs.Upgrade app-emacs/org-mode. | Jul 3, 2024 | Feb 20, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade emacs-filesystem | May 18, 2023 | Feb 20, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade emacs-filesystem | Jul 5, 2023 | Feb 20, 2023 |
| Oracle_linux | — | Upgrade emacs-noxUpgrade emacsUpgrade emacs-commonUpgrade emacs-filesystemUpgrade emacs-lucid | May 17, 2023 | Feb 21, 2023 |
| Redhat_linux | — | Upgrade emacs-nox-debuginfoUpgrade emacs-commonUpgrade emacs-common-debuginfoUpgrade emacs-filesystemUpgrade emacs-lucidUpgrade emacsUpgrade emacs-lucid-debuginfoUpgrade emacs-debuginfoUpgrade emacs-noxUpgrade emacs-debugsourceNo solution exists | May 15, 2023 | Feb 20, 2023 |
| Suse | — | Upgrade emacs-infoUpgrade emacs-noxUpgrade emacs-x11Upgrade etagsUpgrade emacs-elUpgrade emacs | Mar 3, 2023 | Feb 20, 2023 |
| Ubuntu | — | Upgrade emacs-commonUpgrade emacs25 (Ubuntu Pro)Upgrade emacs24-common (Ubuntu Pro)Upgrade emacs-bin-commonUpgrade emacs-common (Ubuntu Pro)Upgrade emacs25-bin-common (Ubuntu Pro)Upgrade emacs24-el (Ubuntu Pro)Upgrade emacs-elUpgrade emacs24 (Ubuntu Pro)Upgrade emacs24-bin-common (Ubuntu Pro)Upgrade emacs-bin-common (Ubuntu Pro)Upgrade emacsUpgrade emacs (Ubuntu Pro)Upgrade emacs25-common (Ubuntu Pro)Upgrade emacs-el (Ubuntu Pro)Upgrade emacs25-el (Ubuntu Pro) | Sep 20, 2024 | Feb 20, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 20, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub