An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.
CVSS Details
- CVSS 3.1 Base Score: 7.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-emacsalma-upgrade-emacs-commonalma-upgrade-emacs-filesystemalma-upgrade-emacs-lucidalma-upgrade-emacs-nox | May 15, 2023 | Feb 20, 2023 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-emacsamazon-linux-ami-2-upgrade-emacs-commonamazon-linux-ami-2-upgrade-emacs-debuginfoamazon-linux-ami-2-upgrade-emacs-develamazon-linux-ami-2-upgrade-emacs-filesystemamazon-linux-ami-2-upgrade-emacs-lucidamazon-linux-ami-2-upgrade-emacs-noxamazon-linux-ami-2-upgrade-emacs-terminal | Mar 7, 2023 | Feb 20, 2023 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-emacsamazon-linux-2023-upgrade-emacs-commonamazon-linux-2023-upgrade-emacs-common-debuginfoamazon-linux-2023-upgrade-emacs-debuginfoamazon-linux-2023-upgrade-emacs-debugsourceamazon-linux-2023-upgrade-emacs-develamazon-linux-2023-upgrade-emacs-filesystemamazon-linux-2023-upgrade-emacs-lucidamazon-linux-2023-upgrade-emacs-lucid-debuginfoamazon-linux-2023-upgrade-emacs-noxamazon-linux-2023-upgrade-emacs-nox-debuginfoamazon-linux-2023-upgrade-emacs-terminal | Feb 17, 2025 | Feb 21, 2023 | |
| Centos_linux | — | centos-upgrade-emacscentos-upgrade-emacs-commoncentos-upgrade-emacs-common-debuginfocentos-upgrade-emacs-debuginfocentos-upgrade-emacs-debugsourcecentos-upgrade-emacs-filesystemcentos-upgrade-emacs-lucidcentos-upgrade-emacs-lucid-debuginfocentos-upgrade-emacs-noxcentos-upgrade-emacs-nox-debuginfo | May 15, 2023 | Feb 20, 2023 |
| Debian | debian-upgrade-emacs | Feb 27, 2023 | Feb 20, 2023 | |
| Freebsd | freebsd-upgrade-package-emacsfreebsd-upgrade-package-emacs-cannafreebsd-upgrade-package-emacs-noxfreebsd-upgrade-package-emacs-develfreebsd-upgrade-package-emacs-devel-nox | Feb 28, 2023 | Feb 27, 2023 | |
| Gentoo Linux | gentoo-linux-upgrade-app-editors-emacsgentoo-linux-upgrade-app-emacs-org-mode | Jul 3, 2024 | Feb 20, 2023 | |
| Huawei Euleros 2_0_sp10 | huawei-euleros-2_0_sp10-upgrade-emacs-filesystem | May 18, 2023 | Feb 20, 2023 | |
| Huawei Euleros 2_0_sp11 | huawei-euleros-2_0_sp11-upgrade-emacs-filesystem | Jul 5, 2023 | Feb 20, 2023 | |
| Oracle_linux | — | oracle-linux-upgrade-emacsoracle-linux-upgrade-emacs-commonoracle-linux-upgrade-emacs-filesystemoracle-linux-upgrade-emacs-lucidoracle-linux-upgrade-emacs-nox | May 17, 2023 | Feb 21, 2023 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-emacsredhat-upgrade-emacs-commonredhat-upgrade-emacs-common-debuginforedhat-upgrade-emacs-debuginforedhat-upgrade-emacs-debugsourceredhat-upgrade-emacs-filesystemredhat-upgrade-emacs-lucidredhat-upgrade-emacs-lucid-debuginforedhat-upgrade-emacs-noxredhat-upgrade-emacs-nox-debuginfo | May 15, 2023 | Feb 20, 2023 | |
| Suse | — | suse-upgrade-emacssuse-upgrade-emacs-elsuse-upgrade-emacs-infosuse-upgrade-emacs-noxsuse-upgrade-emacs-x11suse-upgrade-etags | Mar 3, 2023 | Feb 20, 2023 |
| Ubuntu | ubuntu-pro-upgrade-emacsubuntu-pro-upgrade-emacs-bin-commonubuntu-pro-upgrade-emacs-commonubuntu-pro-upgrade-emacs-elubuntu-pro-upgrade-emacs24ubuntu-pro-upgrade-emacs24-bin-commonubuntu-pro-upgrade-emacs24-commonubuntu-pro-upgrade-emacs24-elubuntu-pro-upgrade-emacs25ubuntu-pro-upgrade-emacs25-bin-commonubuntu-pro-upgrade-emacs25-commonubuntu-pro-upgrade-emacs25-elubuntu-upgrade-emacsubuntu-upgrade-emacs-bin-commonubuntu-upgrade-emacs-commonubuntu-upgrade-emacs-el | Sep 20, 2024 | Feb 20, 2023 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Feb 20, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub