emacs: command injection vulnerability in htmlfontify.el
Published Feb 20, 2023
7.8
HIGHCVSS 3.1
EPSS 1.14%
Description
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.
Affected products
No data.
No data.
Red Hat Enterprise Linux 7
emacs-1:24.3-23.el7_9.1
Fixed · RHSA-2023:3481
Red Hat Enterprise Linux 8
emacs-1:26.1-11.el8
Fixed · RHSA-2023:7083
Red Hat Enterprise Linux 8
emacs-1:26.1-11.el8
Fixed · RHSA-2023:7083
Red Hat Enterprise Linux 8.6 Extended Update Support
emacs-1:26.1-7.el8_6.3
Fixed · RHSA-2024:1103
Red Hat Enterprise Linux 8.8 Extended Update Support
emacs-1:26.1-10.el8_8.4
Fixed · RHSA-2024:1408
Red Hat Enterprise Linux 9
emacs-1:27.2-8.el9_2.1
Fixed · RHSA-2023:2626
Red Hat Enterprise Linux 6
emacs
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | emacs-1:24.3-23.el7_9.1 | Fixed | RHSA-2023:3481 |
| Red Hat Enterprise Linux 8 | emacs-1:26.1-11.el8 | Fixed | RHSA-2023:7083 |
| Red Hat Enterprise Linux 8 | emacs-1:26.1-11.el8 | Fixed | RHSA-2023:7083 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | emacs-1:26.1-7.el8_6.3 | Fixed | RHSA-2024:1103 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | emacs-1:26.1-10.el8_8.4 | Fixed | RHSA-2024:1408 |
| Red Hat Enterprise Linux 9 | emacs-1:27.2-8.el9_2.1 | Fixed | RHSA-2023:2626 |
| Red Hat Enterprise Linux 6 | emacs | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is only triggered when a local user introduces untrusted input, via a file or directory with a crafted name. For this reason, this flaw has been rated with a Moderate security impact.
References (10)
- https://access.redhat.com/security/cve/CVE-2022-48339 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2171989 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-51039 Advisory
- https://git.savannah.gnu.org/cgit/emacs.git/commit/?id=1b4dc4691c1f87fc970fbe568b43869a15ad0d4c Patch
- https://lists.debian.org/debian-lts-announce/2023/05/msg00008.html mailing-list
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FLPQ4K6H2S5TY3L5UDN4K4B3L5RQJYQ6/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6HDBUQNAH2WL4MHWCTUZLN7NGF7CHTK/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-48339
- https://www.cve.org/CVERecord?id=CVE-2022-48339
- https://www.debian.org/security/2023/dsa-5360 vendor-advisoryThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data