An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade emacs-lucidUpgrade emacs-noxUpgrade emacsUpgrade emacs-filesystemUpgrade emacs-common | May 15, 2023 | Feb 20, 2023 |
| Amazon Linux Ami 2 | — | Upgrade emacs-develUpgrade emacs-commonUpgrade emacs-debuginfoUpgrade emacs-noxUpgrade emacs-terminalUpgrade emacs-filesystemUpgrade emacs-lucidUpgrade emacs | Mar 7, 2023 | Feb 20, 2023 |
| Amazon_linux_2023 | — | Upgrade emacs-lucid-debuginfoUpgrade emacs-filesystemUpgrade emacs-common-debuginfoUpgrade emacs-develUpgrade emacs-nox-debuginfoUpgrade emacsUpgrade emacs-terminalUpgrade emacs-debuginfoUpgrade emacs-commonUpgrade emacs-debugsourceUpgrade emacs-noxUpgrade emacs-lucid | Feb 17, 2025 | Feb 21, 2023 |
| Centos_linux | — | Upgrade emacs-debuginfoUpgrade emacs-debugsourceUpgrade emacs-commonUpgrade emacs-noxUpgrade emacs-lucid-debuginfoUpgrade emacsUpgrade emacs-lucidUpgrade emacs-common-debuginfoUpgrade emacs-nox-debuginfoUpgrade emacs-filesystem | May 15, 2023 | Feb 20, 2023 |
| Debian | — | Upgrade emacs | Feb 27, 2023 | Feb 20, 2023 |
| Freebsd | — | Upgrade emacs-develUpgrade emacs-noxUpgrade emacs-devel-noxUpgrade emacsUpgrade emacs-canna | Feb 28, 2023 | Feb 27, 2023 |
| Gentoo Linux | — | Upgrade app-editors/emacs.Upgrade app-emacs/org-mode. | Jul 3, 2024 | Feb 20, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade emacs-filesystem | May 18, 2023 | Feb 20, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade emacs-filesystem | Jul 5, 2023 | Feb 20, 2023 |
| Oracle_linux | — | Upgrade emacs-lucidUpgrade emacs-filesystemUpgrade emacs-noxUpgrade emacsUpgrade emacs-common | May 17, 2023 | Feb 21, 2023 |
| Redhat_linux | — | Upgrade emacs-debugsourceUpgrade emacs-noxUpgrade emacs-lucid-debuginfoNo solution existsUpgrade emacs-debuginfoUpgrade emacs-common-debuginfoUpgrade emacs-commonUpgrade emacs-filesystemUpgrade emacs-nox-debuginfoUpgrade emacsUpgrade emacs-lucid | May 15, 2023 | Feb 20, 2023 |
| Suse | — | Upgrade emacs-noxUpgrade emacs-infoUpgrade etagsUpgrade emacs-elUpgrade emacsUpgrade emacs-x11 | Mar 3, 2023 | Feb 20, 2023 |
| Ubuntu | — | Upgrade emacs-common (Ubuntu Pro)Upgrade emacs24-bin-common (Ubuntu Pro)Upgrade emacs-commonUpgrade emacs25-bin-common (Ubuntu Pro)Upgrade emacs24-el (Ubuntu Pro)Upgrade emacs25 (Ubuntu Pro)Upgrade emacs-elUpgrade emacs-bin-commonUpgrade emacs24 (Ubuntu Pro)Upgrade emacs24-common (Ubuntu Pro)Upgrade emacs-el (Ubuntu Pro)Upgrade emacsUpgrade emacs-bin-common (Ubuntu Pro)Upgrade emacs25-common (Ubuntu Pro)Upgrade emacs (Ubuntu Pro)Upgrade emacs25-el (Ubuntu Pro) | Sep 20, 2024 | Feb 20, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 20, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub