A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade emacs-noxUpgrade emacs-commonUpgrade emacs-lucidUpgrade emacsUpgrade emacs-filesystemUpgrade emacs-terminal | May 15, 2023 | May 9, 2023 |
| Centos_linux | — | Upgrade emacs-nox-debuginfoUpgrade emacs-lucidUpgrade emacs-common-debuginfoUpgrade emacsUpgrade emacs-filesystemUpgrade emacs-lucid-debuginfoUpgrade emacs-commonUpgrade emacs-debugsourceUpgrade emacs-debuginfoUpgrade emacs-terminalUpgrade emacs-nox | May 15, 2023 | May 9, 2023 |
| Oracle_linux | — | Upgrade emacs-filesystemUpgrade emacsUpgrade emacs-commonUpgrade emacs-noxUpgrade emacs-terminalUpgrade emacs-lucid | May 18, 2023 | May 9, 2023 |
| Redhat_linux | — | Upgrade emacs-debuginfoUpgrade emacs-common-debuginfoUpgrade emacsUpgrade emacs-noxUpgrade emacs-terminalUpgrade emacs-lucidUpgrade emacs-commonUpgrade emacs-lucid-debuginfoUpgrade emacs-nox-debuginfoUpgrade emacs-debugsourceUpgrade emacs-filesystem | May 15, 2023 | May 9, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub