Back

HIGH

emacs: command injection vulnerability in htmlfontify.el

Published Feb 20, 2023

Description

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.

Affected products

Remediation

Red Hat statement

This vulnerability is only triggered when a local user introduces untrusted input, via a file or directory with a crafted name. For this reason, this flaw has been rated with a Moderate security impact.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Feb 20, 2023
Updated Mar 18, 2025
Reserved Feb 20, 2023

CISA Vulnrichment

Updated Mar 18, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Feb 21, 2023
Bugzilla 2171989

ENISA EUVD

Assigner mitre
Published Feb 20, 2023
Updated Mar 18, 2025

GitHub

No data