Security
Headlines
HeadlinesLatestCVEs

Headline

RHSA-2023:3481: Red Hat Security Advisory: emacs security update

An update for emacs is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

Related CVEs:

  • CVE-2022-48339: A flaw was found in the Emacs package. If a file name or directory name contains shell metacharacters, arbitrary code may be executed.
Red Hat Security Data
#vulnerability#web#mac#linux#red_hat#nodejs#js#java#kubernetes#aws#ibm

Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Containers
  • Support Cases

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Virtualization
  • Red Hat Identity Management
  • Red Hat Directory Server
  • Red Hat Certificate System
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Update Infrastructure
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat CloudForms
  • Red Hat OpenStack Platform
  • Red Hat OpenShift Container Platform
  • Red Hat OpenShift Data Science
  • Red Hat OpenShift Online
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat CodeReady Workspaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat Single Sign On
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Thorntail
  • Red Hat build of Eclipse Vert.x
  • Red Hat build of OpenJDK
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Process Automation
  • Red Hat Process Automation Manager
  • Red Hat Decision Manager

All Products

Issued:

2023-06-06

Updated:

2023-06-06

RHSA-2023:3481 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: emacs security update

Type/Severity

Security Advisory: Moderate

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for emacs is now available for Red Hat Enterprise Linux 7.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

GNU Emacs is a powerful, customizable, self-documenting text editor. It provides special code editing features, a scripting language (elisp), and the capability to read e-mail and news.

Security Fix(es):

  • emacs: command injection vulnerability in htmlfontify.el (CVE-2022-48339)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected Products

  • Red Hat Enterprise Linux Server 7 x86_64
  • Red Hat Enterprise Linux Workstation 7 x86_64
  • Red Hat Enterprise Linux Desktop 7 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 7 s390x
  • Red Hat Enterprise Linux for Power, big endian 7 ppc64
  • Red Hat Enterprise Linux for Scientific Computing 7 x86_64
  • Red Hat Enterprise Linux for Power, little endian 7 ppc64le

Fixes

  • BZ - 2171989 - CVE-2022-48339 emacs: command injection vulnerability in htmlfontify.el

Red Hat Enterprise Linux Server 7

SRPM

emacs-24.3-23.el7_9.1.src.rpm

SHA-256: ec4322b6cc8eb9b2c3bafb8fce4ec9cc8e0cf4cd8d88d7de1a3dbd8cc3798b50

x86_64

emacs-24.3-23.el7_9.1.x86_64.rpm

SHA-256: 17a442dd50e81a8fefcf3d472990137382332b06ff39b30ed6260738f6a3ff60

emacs-common-24.3-23.el7_9.1.x86_64.rpm

SHA-256: 55e113e16cea0be4683c18a0344c7106d31b6c639941333175cf828446499933

emacs-debuginfo-24.3-23.el7_9.1.x86_64.rpm

SHA-256: 7a4b7a961ee3b9ad6ab3a1c91d3b5d7fadd5b0fa457fdde36dff406a8fdff81a

emacs-el-24.3-23.el7_9.1.noarch.rpm

SHA-256: 69f489e429b6aa6c07352a54bdd347130d1eeeea725cb3498855429ad2d27168

emacs-filesystem-24.3-23.el7_9.1.noarch.rpm

SHA-256: b079dbe32300a57548e4396df3f3cda9a2865470935572899e83a6b0128556b4

emacs-nox-24.3-23.el7_9.1.x86_64.rpm

SHA-256: ed9692978fd576608641649553d80ca578fcba7dda72995cb268e1d9231a98b2

emacs-terminal-24.3-23.el7_9.1.noarch.rpm

SHA-256: e280ed8869a04c9a2dc7dcaba4556cac84f04dc66f42c9f3613db14e382a28ca

Red Hat Enterprise Linux Workstation 7

SRPM

emacs-24.3-23.el7_9.1.src.rpm

SHA-256: ec4322b6cc8eb9b2c3bafb8fce4ec9cc8e0cf4cd8d88d7de1a3dbd8cc3798b50

x86_64

emacs-24.3-23.el7_9.1.x86_64.rpm

SHA-256: 17a442dd50e81a8fefcf3d472990137382332b06ff39b30ed6260738f6a3ff60

emacs-common-24.3-23.el7_9.1.x86_64.rpm

SHA-256: 55e113e16cea0be4683c18a0344c7106d31b6c639941333175cf828446499933

emacs-debuginfo-24.3-23.el7_9.1.x86_64.rpm

SHA-256: 7a4b7a961ee3b9ad6ab3a1c91d3b5d7fadd5b0fa457fdde36dff406a8fdff81a

emacs-el-24.3-23.el7_9.1.noarch.rpm

SHA-256: 69f489e429b6aa6c07352a54bdd347130d1eeeea725cb3498855429ad2d27168

emacs-filesystem-24.3-23.el7_9.1.noarch.rpm

SHA-256: b079dbe32300a57548e4396df3f3cda9a2865470935572899e83a6b0128556b4

emacs-nox-24.3-23.el7_9.1.x86_64.rpm

SHA-256: ed9692978fd576608641649553d80ca578fcba7dda72995cb268e1d9231a98b2

emacs-terminal-24.3-23.el7_9.1.noarch.rpm

SHA-256: e280ed8869a04c9a2dc7dcaba4556cac84f04dc66f42c9f3613db14e382a28ca

Red Hat Enterprise Linux Desktop 7

SRPM

emacs-24.3-23.el7_9.1.src.rpm

SHA-256: ec4322b6cc8eb9b2c3bafb8fce4ec9cc8e0cf4cd8d88d7de1a3dbd8cc3798b50

x86_64

emacs-24.3-23.el7_9.1.x86_64.rpm

SHA-256: 17a442dd50e81a8fefcf3d472990137382332b06ff39b30ed6260738f6a3ff60

emacs-common-24.3-23.el7_9.1.x86_64.rpm

SHA-256: 55e113e16cea0be4683c18a0344c7106d31b6c639941333175cf828446499933

emacs-debuginfo-24.3-23.el7_9.1.x86_64.rpm

SHA-256: 7a4b7a961ee3b9ad6ab3a1c91d3b5d7fadd5b0fa457fdde36dff406a8fdff81a

emacs-el-24.3-23.el7_9.1.noarch.rpm

SHA-256: 69f489e429b6aa6c07352a54bdd347130d1eeeea725cb3498855429ad2d27168

emacs-filesystem-24.3-23.el7_9.1.noarch.rpm

SHA-256: b079dbe32300a57548e4396df3f3cda9a2865470935572899e83a6b0128556b4

emacs-nox-24.3-23.el7_9.1.x86_64.rpm

SHA-256: ed9692978fd576608641649553d80ca578fcba7dda72995cb268e1d9231a98b2

emacs-terminal-24.3-23.el7_9.1.noarch.rpm

SHA-256: e280ed8869a04c9a2dc7dcaba4556cac84f04dc66f42c9f3613db14e382a28ca

Red Hat Enterprise Linux for IBM z Systems 7

SRPM

emacs-24.3-23.el7_9.1.src.rpm

SHA-256: ec4322b6cc8eb9b2c3bafb8fce4ec9cc8e0cf4cd8d88d7de1a3dbd8cc3798b50

s390x

emacs-24.3-23.el7_9.1.s390x.rpm

SHA-256: facad29075e7f9936e61beff737adc4a24574ea754827940889504de6aae8017

emacs-common-24.3-23.el7_9.1.s390x.rpm

SHA-256: 619335c78f210bc44bd9bf6da1c576054db7e6105d2c96b22e19fea263994bc5

emacs-debuginfo-24.3-23.el7_9.1.s390x.rpm

SHA-256: 24e54a9570340315fb7aeef6e872ddf1a69763b7a77a06a439bc2c31411e81be

emacs-el-24.3-23.el7_9.1.noarch.rpm

SHA-256: 69f489e429b6aa6c07352a54bdd347130d1eeeea725cb3498855429ad2d27168

emacs-filesystem-24.3-23.el7_9.1.noarch.rpm

SHA-256: b079dbe32300a57548e4396df3f3cda9a2865470935572899e83a6b0128556b4

emacs-nox-24.3-23.el7_9.1.s390x.rpm

SHA-256: 8893761a7024828087846a68981656522c5441a8d126e9aacd8e22668bed3d51

emacs-terminal-24.3-23.el7_9.1.noarch.rpm

SHA-256: e280ed8869a04c9a2dc7dcaba4556cac84f04dc66f42c9f3613db14e382a28ca

Red Hat Enterprise Linux for Power, big endian 7

SRPM

emacs-24.3-23.el7_9.1.src.rpm

SHA-256: ec4322b6cc8eb9b2c3bafb8fce4ec9cc8e0cf4cd8d88d7de1a3dbd8cc3798b50

ppc64

emacs-24.3-23.el7_9.1.ppc64.rpm

SHA-256: 810661001efc102047b31762b1f408618d8fa450be0fb62d70f5f47793908562

emacs-common-24.3-23.el7_9.1.ppc64.rpm

SHA-256: c64a6ee5a1c8e45f6b39db49dbf66b9b397034355c0a67df73a82b42f7e06f4b

emacs-debuginfo-24.3-23.el7_9.1.ppc64.rpm

SHA-256: 920d5ac60c31e3be484d3b03549221a9c12183bc9e542088392437c47fa17b6b

emacs-el-24.3-23.el7_9.1.noarch.rpm

SHA-256: 69f489e429b6aa6c07352a54bdd347130d1eeeea725cb3498855429ad2d27168

emacs-filesystem-24.3-23.el7_9.1.noarch.rpm

SHA-256: b079dbe32300a57548e4396df3f3cda9a2865470935572899e83a6b0128556b4

emacs-nox-24.3-23.el7_9.1.ppc64.rpm

SHA-256: 7756f66eabb433d1aee4337840ddaa0505df9c1d2b8f592714b812c1dd5dc420

emacs-terminal-24.3-23.el7_9.1.noarch.rpm

SHA-256: e280ed8869a04c9a2dc7dcaba4556cac84f04dc66f42c9f3613db14e382a28ca

Red Hat Enterprise Linux for Scientific Computing 7

SRPM

emacs-24.3-23.el7_9.1.src.rpm

SHA-256: ec4322b6cc8eb9b2c3bafb8fce4ec9cc8e0cf4cd8d88d7de1a3dbd8cc3798b50

x86_64

emacs-24.3-23.el7_9.1.x86_64.rpm

SHA-256: 17a442dd50e81a8fefcf3d472990137382332b06ff39b30ed6260738f6a3ff60

emacs-common-24.3-23.el7_9.1.x86_64.rpm

SHA-256: 55e113e16cea0be4683c18a0344c7106d31b6c639941333175cf828446499933

emacs-debuginfo-24.3-23.el7_9.1.x86_64.rpm

SHA-256: 7a4b7a961ee3b9ad6ab3a1c91d3b5d7fadd5b0fa457fdde36dff406a8fdff81a

emacs-el-24.3-23.el7_9.1.noarch.rpm

SHA-256: 69f489e429b6aa6c07352a54bdd347130d1eeeea725cb3498855429ad2d27168

emacs-filesystem-24.3-23.el7_9.1.noarch.rpm

SHA-256: b079dbe32300a57548e4396df3f3cda9a2865470935572899e83a6b0128556b4

emacs-nox-24.3-23.el7_9.1.x86_64.rpm

SHA-256: ed9692978fd576608641649553d80ca578fcba7dda72995cb268e1d9231a98b2

emacs-terminal-24.3-23.el7_9.1.noarch.rpm

SHA-256: e280ed8869a04c9a2dc7dcaba4556cac84f04dc66f42c9f3613db14e382a28ca

Red Hat Enterprise Linux for Power, little endian 7

SRPM

emacs-24.3-23.el7_9.1.src.rpm

SHA-256: ec4322b6cc8eb9b2c3bafb8fce4ec9cc8e0cf4cd8d88d7de1a3dbd8cc3798b50

ppc64le

emacs-24.3-23.el7_9.1.ppc64le.rpm

SHA-256: 3eadd3ce55f43da9e5312a0eacefe8a1ef3d11cb7df64341857092da2f7f9709

emacs-common-24.3-23.el7_9.1.ppc64le.rpm

SHA-256: 2089706dba4b8ae249e467c85cb99c81b60e34c9b073b4b7845eb9449397b01c

emacs-debuginfo-24.3-23.el7_9.1.ppc64le.rpm

SHA-256: 9d8d685b0e1bb774cd7fa686a7a552a4f6f6a56d84106988e078cabf0e1c73a2

emacs-el-24.3-23.el7_9.1.noarch.rpm

SHA-256: 69f489e429b6aa6c07352a54bdd347130d1eeeea725cb3498855429ad2d27168

emacs-filesystem-24.3-23.el7_9.1.noarch.rpm

SHA-256: b079dbe32300a57548e4396df3f3cda9a2865470935572899e83a6b0128556b4

emacs-nox-24.3-23.el7_9.1.ppc64le.rpm

SHA-256: 73c0c9835a7e77f63ad2563c9067cf96c37c5cc65d269a114a9f4b7b19b52099

emacs-terminal-24.3-23.el7_9.1.noarch.rpm

SHA-256: e280ed8869a04c9a2dc7dcaba4556cac84f04dc66f42c9f3613db14e382a28ca

The Red Hat security contact is [email protected]. More contact details at https://access.redhat.com/security/team/contact/.

Related news

Ubuntu Security Notice USN-7027-1

Ubuntu Security Notice 7027-1 - It was discovered that Emacs incorrectly handled input sanitization. An attacker could possibly use this issue to execute arbitrary commands. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. Xi Lu discovered that Emacs incorrectly handled input sanitization. An attacker could possibly use this issue to execute arbitrary commands. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.

Gentoo Linux Security Advisory 202407-08

Gentoo Linux Security Advisory 202407-8 - Multiple vulnerabilities have been discovered in GNU Emacs and Org Mode, the worst of which could lead to arbitrary code execution. Versions greater than or equal to 26.3-r16:26 are affected.

Red Hat Security Advisory 2024-1408-03

Red Hat Security Advisory 2024-1408-03 - An update for emacs is now available for Red Hat Enterprise Linux 8.8 Extended Update Support. Issues addressed include a code execution vulnerability.

Red Hat Security Advisory 2023-7083-01

Red Hat Security Advisory 2023-7083-01 - An update for emacs is now available for Red Hat Enterprise Linux 8. Issues addressed include a code execution vulnerability.

CVE-2023-30994: Security Bulletin: IBM QRadar SIEM includes components with known vulnerabilities

IBM QRadar SIEM 7.5.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 254138

Red Hat Security Advisory 2023-3742-02

Red Hat Security Advisory 2023-3742-02 - Red Hat OpenShift Data Foundation is software-defined storage integrated with and optimized for the Red Hat OpenShift Container Platform. Red Hat OpenShift Data Foundation is a highly scalable, production-grade persistent storage for stateful applications running in the Red Hat OpenShift Container Platform. Issues addressed include bypass, denial of service, and remote SQL injection vulnerabilities.

RHSA-2023:3742: Red Hat Security Advisory: Red Hat OpenShift Data Foundation 4.13.0 security and bug fix update

Updated images that include numerous enhancements, security, and bug fixes are now available in Red Hat Container Registry for Red Hat OpenShift Data Foundation 4.13.0 on Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2020-16250: A flaw was found in Vault and Vault Enterprise (“Vault”). In the affected versions of Vault, with the AWS Auth Method configured and under certain circumstances, the values relied upon by Vault to validate AWS IAM ident...

Red Hat Security Advisory 2023-3481-01

Red Hat Security Advisory 2023-3481-01 - GNU Emacs is a powerful, customizable, self-documenting text editor. It provides special code editing features, a scripting language, and the capability to read e-mail and news. Issues addressed include a code execution vulnerability.

Red Hat Security Advisory 2023-2626-01

Red Hat Security Advisory 2023-2626-01 - GNU Emacs is a powerful, customizable, self-documenting text editor. It provides special code editing features, a scripting language, and the capability to read e-mail and news. Issues addressed include a code execution vulnerability.

RHSA-2023:2626: Red Hat Security Advisory: emacs security update

An update for emacs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2022-48337: A flaw was found in the Emacs package. This flaw allows attackers to execute commands via shell metacharacters in the name of a source-code file. * CVE-2022-48338: A flaw was found in the Emacs package. A malicious ruby source file may cause a local command injection. * CVE-2022-48339: A flaw was found in the Emacs package. If a file name or direc...

Ubuntu Security Notice USN-5955-1

Ubuntu Security Notice 5955-1 - It was discovered that Emacs did not properly manage certain files when using htmlfontify functionality. A local attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary commands.

Debian Security Advisory 5360-1

Debian Linux Security Advisory 5360-1 - Xi Lu discovered that missing input sanitising in Emacs (in etags, the Ruby mode and htmlfontify) could result in the execution of arbitrary shell commands.

CVE-2022-48339

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.