An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade emacs-lucidUpgrade emacsUpgrade emacs-noxUpgrade emacs-filesystemUpgrade emacs-common | May 15, 2023 | Feb 20, 2023 |
| Amazon Linux Ami 2 | — | Upgrade emacs-develUpgrade emacs-commonUpgrade emacs-terminalUpgrade emacs-filesystemUpgrade emacs-debuginfoUpgrade emacs-lucidUpgrade emacs-noxUpgrade emacs | Mar 7, 2023 | Feb 20, 2023 |
| Amazon_linux_2023 | — | Upgrade emacsUpgrade emacs-lucid-debuginfoUpgrade emacs-filesystemUpgrade emacs-common-debuginfoUpgrade emacs-develUpgrade emacs-nox-debuginfoUpgrade emacs-debugsourceUpgrade emacs-noxUpgrade emacs-lucidUpgrade emacs-commonUpgrade emacs-terminalUpgrade emacs-debuginfo | Feb 17, 2025 | Feb 21, 2023 |
| Centos_linux | — | Upgrade emacs-lucid-debuginfoUpgrade emacsUpgrade emacs-common-debuginfoUpgrade emacs-lucidUpgrade emacs-filesystemUpgrade emacs-nox-debuginfoUpgrade emacs-debugsourceUpgrade emacs-debuginfoUpgrade emacs-commonUpgrade emacs-nox | May 15, 2023 | Feb 20, 2023 |
| Debian | — | Upgrade emacs | Feb 27, 2023 | Feb 20, 2023 |
| Freebsd | — | Upgrade emacs-cannaUpgrade emacsUpgrade emacs-devel-noxUpgrade emacs-develUpgrade emacs-nox | Feb 28, 2023 | Feb 27, 2023 |
| Gentoo Linux | — | Upgrade app-emacs/org-mode.Upgrade app-editors/emacs. | Jul 3, 2024 | Feb 20, 2023 |
| Huawei Euleros 2_0_sp10 | — | Upgrade emacs-filesystem | May 18, 2023 | Feb 20, 2023 |
| Huawei Euleros 2_0_sp11 | — | Upgrade emacs-filesystem | Jul 5, 2023 | Feb 20, 2023 |
| Oracle_linux | — | Upgrade emacs-lucidUpgrade emacs-filesystemUpgrade emacsUpgrade emacs-noxUpgrade emacs-common | May 17, 2023 | Feb 21, 2023 |
| Redhat_linux | — | Upgrade emacsUpgrade emacs-lucidUpgrade emacs-commonUpgrade emacs-filesystemUpgrade emacs-nox-debuginfoUpgrade emacs-common-debuginfoUpgrade emacs-noxUpgrade emacs-debugsourceUpgrade emacs-debuginfoNo solution existsUpgrade emacs-lucid-debuginfo | May 15, 2023 | Feb 20, 2023 |
| Suse | — | Upgrade emacs-x11Upgrade emacs-elUpgrade etagsUpgrade emacsUpgrade emacs-noxUpgrade emacs-info | Mar 3, 2023 | Feb 20, 2023 |
| Ubuntu | — | Upgrade emacs-commonUpgrade emacs24-el (Ubuntu Pro)Upgrade emacs24 (Ubuntu Pro)Upgrade emacs-elUpgrade emacs24-common (Ubuntu Pro)Upgrade emacs25-bin-common (Ubuntu Pro)Upgrade emacs-common (Ubuntu Pro)Upgrade emacs-bin-commonUpgrade emacs24-bin-common (Ubuntu Pro)Upgrade emacs25 (Ubuntu Pro)Upgrade emacs-el (Ubuntu Pro)Upgrade emacs25-common (Ubuntu Pro)Upgrade emacs25-el (Ubuntu Pro)Upgrade emacsUpgrade emacs-bin-common (Ubuntu Pro)Upgrade emacs (Ubuntu Pro) | Sep 20, 2024 | Feb 20, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 20, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub