Back

HIGH

emacs: command injection flaw within "enriched mode" handling

Published Sep 14, 2017

Description

GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).

Affected products

Remediation

Red Hat mitigation

This issue can be mitigated by adding the following lines to the Emacs init file (for example ~/.emacs, ~/emacs.d/init.el, site-start.el) and avoiding options that would bypass normal initialization, like 'emacs -Q': ;; Mitigate CVE-2017-14482 in Emacs 25.2 and earlier (require 'enriched) (defun enriched-decode-display-prop (start end &optional param) (list start end))

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 14, 2017
Updated Aug 5, 2024
Reserved Sep 14, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 4, 2017