A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade emacs-noxUpgrade emacs-commonUpgrade emacs-lucidUpgrade emacs-terminalUpgrade emacs-filesystemUpgrade emacs | May 15, 2023 | May 9, 2023 |
| Centos_linux | — | Upgrade emacs-debugsourceUpgrade emacs-noxUpgrade emacs-terminalUpgrade emacs-debuginfoUpgrade emacs-lucid-debuginfoUpgrade emacs-common-debuginfoUpgrade emacs-nox-debuginfoUpgrade emacsUpgrade emacs-commonUpgrade emacs-filesystemUpgrade emacs-lucid | May 15, 2023 | May 9, 2023 |
| Oracle_linux | — | Upgrade emacs-commonUpgrade emacs-lucidUpgrade emacs-terminalUpgrade emacsUpgrade emacs-noxUpgrade emacs-filesystem | May 18, 2023 | May 9, 2023 |
| Redhat_linux | — | Upgrade emacs-nox-debuginfoUpgrade emacs-filesystemUpgrade emacs-debugsourceUpgrade emacs-commonUpgrade emacs-lucid-debuginfoUpgrade emacs-lucidUpgrade emacs-noxUpgrade emacs-terminalUpgrade emacs-debuginfoUpgrade emacsUpgrade emacs-common-debuginfo | May 15, 2023 | May 9, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub