A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade emacs-filesystemUpgrade emacs-terminalUpgrade emacsUpgrade emacs-noxUpgrade emacs-commonUpgrade emacs-lucid | May 15, 2023 | May 9, 2023 |
| Centos_linux | — | Upgrade emacs-filesystemUpgrade emacs-nox-debuginfoUpgrade emacs-commonUpgrade emacs-lucid-debuginfoUpgrade emacs-lucidUpgrade emacs-common-debuginfoUpgrade emacsUpgrade emacs-debuginfoUpgrade emacs-noxUpgrade emacs-terminalUpgrade emacs-debugsource | May 15, 2023 | May 9, 2023 |
| Oracle_linux | — | Upgrade emacs-commonUpgrade emacs-noxUpgrade emacs-lucidUpgrade emacs-terminalUpgrade emacsUpgrade emacs-filesystem | May 18, 2023 | May 9, 2023 |
| Redhat_linux | — | Upgrade emacs-common-debuginfoUpgrade emacs-terminalUpgrade emacsUpgrade emacs-debuginfoUpgrade emacs-lucidUpgrade emacs-noxUpgrade emacs-filesystemUpgrade emacs-debugsourceUpgrade emacs-lucid-debuginfoUpgrade emacs-commonUpgrade emacs-nox-debuginfo | May 15, 2023 | May 9, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub