Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-85329
HistoryNov 30, 2022 - 12:00 a.m.

GNU Emacs Command Injection Vulnerability

2022-11-3000:00:00
China National Vulnerability Database
www.cnvd.org.cn
10
gnu emacs
command injection
vulnerability
version 28.2
lib-src/etags.c
system c library functions
ctags program
arbitrary commands
exploit

0.001 Low

EPSS

Percentile

34.4%

GNU Emacs is a family of text editors from the GNU community in the U.S. A command injection vulnerability exists in GNU Emacs version 28.2 and earlier, which stems from lib-src/etags.c’s use of system C library functions when implementing the ctags program. An attacker could exploit the vulnerability to execute arbitrary commands.

CPENameOperatorVersion
gnu gnu emacsle28.2