Lucene search

K
centosCentOS ProjectCESA-2023:3481
HistoryJul 27, 2023 - 2:34 p.m.

emacs security update

2023-07-2714:34:56
CentOS Project
lists.centos.org
253
centos
security fix
command injection
vulnerability
cve
cvss
acknowledgments
affected packages
upstream details

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

25.1%

CentOS Errata and Security Advisory CESA-2023:3481

GNU Emacs is a powerful, customizable, self-documenting text editor. It provides special code editing features, a scripting language (elisp), and the capability to read e-mail and news.

Security Fix(es):

  • emacs: command injection vulnerability in htmlfontify.el (CVE-2022-48339)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2023-July/086401.html

Affected packages:
emacs
emacs-common
emacs-el
emacs-filesystem
emacs-nox
emacs-terminal

Upstream details at:
https://access.redhat.com/errata/RHSA-2023:3481

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

0.001 Low

EPSS

Percentile

25.1%