An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade emacs-lucidUpgrade emacsUpgrade emacs-noxUpgrade emacs-filesystemUpgrade emacs-common | May 15, 2023 | Feb 20, 2023 |
| Amazon Linux Ami 2 | — | Upgrade emacs-develUpgrade emacs-commonUpgrade emacs-debuginfoUpgrade emacsUpgrade emacs-filesystemUpgrade emacs-terminalUpgrade emacs-noxUpgrade emacs-lucid | Mar 7, 2023 | Feb 20, 2023 |
| Amazon_linux_2023 | — | Upgrade emacs-lucid-debuginfoUpgrade emacs-common-debuginfoUpgrade emacs-nox-debuginfoUpgrade emacsUpgrade emacs-filesystemUpgrade emacs-develUpgrade emacs-noxUpgrade emacs-debuginfoUpgrade emacs-commonUpgrade emacs-lucidUpgrade emacs-debugsourceUpgrade emacs-terminal | Feb 17, 2025 | Feb 21, 2023 |
| Centos_linux | — | Upgrade emacs-debuginfoUpgrade emacs-commonUpgrade emacs-noxUpgrade emacs-debugsourceUpgrade emacs-lucid-debuginfoUpgrade emacs-nox-debuginfoUpgrade emacs-lucidUpgrade emacsUpgrade emacs-filesystemUpgrade emacs-common-debuginfo | May 15, 2023 | Feb 20, 2023 |
| Debian | — | Upgrade emacs | Feb 27, 2023 | Feb 20, 2023 |
| Freebsd | — | Upgrade emacs-develUpgrade emacs-noxUpgrade emacs-devel-noxUpgrade emacsUpgrade emacs-canna | Feb 28, 2023 | Feb 27, 2023 |
| Gentoo Linux | — | Upgrade app-emacs/org-mode.Upgrade app-editors/emacs. | Jul 3, 2024 | Feb 20, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade emacs-filesystem | May 18, 2023 | Feb 20, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade emacs-filesystem | Jul 5, 2023 | Feb 20, 2023 |
| Oracle_linux | — | Upgrade emacs-filesystemUpgrade emacs-lucidUpgrade emacsUpgrade emacs-commonUpgrade emacs-nox | May 17, 2023 | Feb 21, 2023 |
| Redhat_linux | — | Upgrade emacs-nox-debuginfoUpgrade emacs-common-debuginfoUpgrade emacs-filesystemUpgrade emacs-commonUpgrade emacsUpgrade emacs-lucidNo solution existsUpgrade emacs-lucid-debuginfoUpgrade emacs-debugsourceUpgrade emacs-debuginfoUpgrade emacs-nox | May 15, 2023 | Feb 20, 2023 |
| Suse | — | Upgrade emacs-elUpgrade emacs-x11Upgrade etagsUpgrade emacsUpgrade emacs-noxUpgrade emacs-info | Mar 3, 2023 | Feb 20, 2023 |
| Ubuntu | — | Upgrade emacs24-el (Ubuntu Pro)Upgrade emacs25-bin-common (Ubuntu Pro)Upgrade emacs-elUpgrade emacs24 (Ubuntu Pro)Upgrade emacs-commonUpgrade emacs24-bin-common (Ubuntu Pro)Upgrade emacs24-common (Ubuntu Pro)Upgrade emacs-common (Ubuntu Pro)Upgrade emacs25 (Ubuntu Pro)Upgrade emacs-bin-commonUpgrade emacs (Ubuntu Pro)Upgrade emacs-bin-common (Ubuntu Pro)Upgrade emacs-el (Ubuntu Pro)Upgrade emacsUpgrade emacs25-common (Ubuntu Pro)Upgrade emacs25-el (Ubuntu Pro) | Sep 20, 2024 | Feb 20, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 20, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub