OESA-2023-1148

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2023-1148
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2023-1148.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2023-1148
Upstream
Published
2023-03-04T11:05:00Z
Modified
2025-08-12T05:16:23.431852Z
Summary
emacs security update
Details

Emacs is the extensible, customizable, self-documenting real-time display editor.At its core is an interpreter for Emacs Lisp, a dialect of the Lisp programming language with extensions to support text editing. And it is an entire ecosystem of functionality beyond text editing,including a project planner, mail and news reader, debugger interface, calendar, and more.

Security Fix(es):

An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be executed.(CVE-2022-48339)

An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.(CVE-2022-48338)

GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command (suggested in the etags documentation) in a situation where the current working directory has contents that depend on untrusted input.(CVE-2022-48337)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / emacs

Package

Name
emacs
Purl
pkg:rpm/openEuler/emacs&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
27.1-10.oe1

Ecosystem specific

{
    "src": [
        "emacs-27.1-10.oe1.src.rpm"
    ],
    "noarch": [
        "emacs-terminal-27.1-10.oe1.noarch.rpm",
        "emacs-filesystem-27.1-10.oe1.noarch.rpm",
        "emacs-help-27.1-10.oe1.noarch.rpm"
    ],
    "aarch64": [
        "emacs-lucid-27.1-10.oe1.aarch64.rpm",
        "emacs-devel-27.1-10.oe1.aarch64.rpm",
        "emacs-common-27.1-10.oe1.aarch64.rpm",
        "emacs-debugsource-27.1-10.oe1.aarch64.rpm",
        "emacs-nox-27.1-10.oe1.aarch64.rpm",
        "emacs-debuginfo-27.1-10.oe1.aarch64.rpm",
        "emacs-27.1-10.oe1.aarch64.rpm"
    ],
    "x86_64": [
        "emacs-debuginfo-27.1-10.oe1.x86_64.rpm",
        "emacs-devel-27.1-10.oe1.x86_64.rpm",
        "emacs-debugsource-27.1-10.oe1.x86_64.rpm",
        "emacs-27.1-10.oe1.x86_64.rpm",
        "emacs-lucid-27.1-10.oe1.x86_64.rpm",
        "emacs-nox-27.1-10.oe1.x86_64.rpm",
        "emacs-common-27.1-10.oe1.x86_64.rpm"
    ]
}

openEuler:20.03-LTS-SP3 / emacs

Package

Name
emacs
Purl
pkg:rpm/openEuler/emacs&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
27.1-8.oe1

Ecosystem specific

{
    "src": [
        "emacs-27.1-8.oe1.src.rpm"
    ],
    "noarch": [
        "emacs-filesystem-27.1-8.oe1.noarch.rpm",
        "emacs-help-27.1-8.oe1.noarch.rpm",
        "emacs-terminal-27.1-8.oe1.noarch.rpm"
    ],
    "aarch64": [
        "emacs-devel-27.1-8.oe1.aarch64.rpm",
        "emacs-debuginfo-27.1-8.oe1.aarch64.rpm",
        "emacs-common-27.1-8.oe1.aarch64.rpm",
        "emacs-27.1-8.oe1.aarch64.rpm",
        "emacs-debugsource-27.1-8.oe1.aarch64.rpm",
        "emacs-lucid-27.1-8.oe1.aarch64.rpm",
        "emacs-nox-27.1-8.oe1.aarch64.rpm"
    ],
    "x86_64": [
        "emacs-common-27.1-8.oe1.x86_64.rpm",
        "emacs-debugsource-27.1-8.oe1.x86_64.rpm",
        "emacs-nox-27.1-8.oe1.x86_64.rpm",
        "emacs-lucid-27.1-8.oe1.x86_64.rpm",
        "emacs-27.1-8.oe1.x86_64.rpm",
        "emacs-debuginfo-27.1-8.oe1.x86_64.rpm",
        "emacs-devel-27.1-8.oe1.x86_64.rpm"
    ]
}

openEuler:22.03-LTS / emacs

Package

Name
emacs
Purl
pkg:rpm/openEuler/emacs&distro=openEuler-22.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
27.2-9.oe2203sp1

Ecosystem specific

{
    "src": [
        "emacs-27.2-9.oe2203.src.rpm",
        "emacs-27.2-9.oe2203sp1.src.rpm"
    ],
    "noarch": [
        "emacs-terminal-27.2-9.oe2203.noarch.rpm",
        "emacs-filesystem-27.2-9.oe2203.noarch.rpm",
        "emacs-help-27.2-9.oe2203.noarch.rpm",
        "emacs-terminal-27.2-9.oe2203sp1.noarch.rpm",
        "emacs-filesystem-27.2-9.oe2203sp1.noarch.rpm",
        "emacs-help-27.2-9.oe2203sp1.noarch.rpm"
    ],
    "aarch64": [
        "emacs-27.2-9.oe2203.aarch64.rpm",
        "emacs-debugsource-27.2-9.oe2203.aarch64.rpm",
        "emacs-nox-27.2-9.oe2203.aarch64.rpm",
        "emacs-lucid-27.2-9.oe2203.aarch64.rpm",
        "emacs-debuginfo-27.2-9.oe2203.aarch64.rpm",
        "emacs-devel-27.2-9.oe2203.aarch64.rpm",
        "emacs-common-27.2-9.oe2203.aarch64.rpm",
        "emacs-devel-27.2-9.oe2203sp1.aarch64.rpm",
        "emacs-lucid-27.2-9.oe2203sp1.aarch64.rpm",
        "emacs-debuginfo-27.2-9.oe2203sp1.aarch64.rpm",
        "emacs-common-27.2-9.oe2203sp1.aarch64.rpm",
        "emacs-debugsource-27.2-9.oe2203sp1.aarch64.rpm",
        "emacs-27.2-9.oe2203sp1.aarch64.rpm",
        "emacs-nox-27.2-9.oe2203sp1.aarch64.rpm"
    ],
    "x86_64": [
        "emacs-lucid-27.2-9.oe2203.x86_64.rpm",
        "emacs-nox-27.2-9.oe2203.x86_64.rpm",
        "emacs-devel-27.2-9.oe2203.x86_64.rpm",
        "emacs-27.2-9.oe2203.x86_64.rpm",
        "emacs-debuginfo-27.2-9.oe2203.x86_64.rpm",
        "emacs-debugsource-27.2-9.oe2203.x86_64.rpm",
        "emacs-common-27.2-9.oe2203.x86_64.rpm",
        "emacs-common-27.2-9.oe2203sp1.x86_64.rpm",
        "emacs-debugsource-27.2-9.oe2203sp1.x86_64.rpm",
        "emacs-devel-27.2-9.oe2203sp1.x86_64.rpm",
        "emacs-lucid-27.2-9.oe2203sp1.x86_64.rpm",
        "emacs-27.2-9.oe2203sp1.x86_64.rpm",
        "emacs-debuginfo-27.2-9.oe2203sp1.x86_64.rpm",
        "emacs-nox-27.2-9.oe2203sp1.x86_64.rpm"
    ]
}

openEuler:22.03-LTS-SP1 / emacs

Package

Name
emacs
Purl
pkg:rpm/openEuler/emacs&distro=openEuler-22.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
27.2-9.oe2203sp1

Ecosystem specific

{
    "src": [
        "emacs-27.2-9.oe2203sp1.src.rpm"
    ],
    "noarch": [
        "emacs-terminal-27.2-9.oe2203sp1.noarch.rpm",
        "emacs-filesystem-27.2-9.oe2203sp1.noarch.rpm",
        "emacs-help-27.2-9.oe2203sp1.noarch.rpm"
    ],
    "aarch64": [
        "emacs-devel-27.2-9.oe2203sp1.aarch64.rpm",
        "emacs-lucid-27.2-9.oe2203sp1.aarch64.rpm",
        "emacs-debuginfo-27.2-9.oe2203sp1.aarch64.rpm",
        "emacs-common-27.2-9.oe2203sp1.aarch64.rpm",
        "emacs-debugsource-27.2-9.oe2203sp1.aarch64.rpm",
        "emacs-27.2-9.oe2203sp1.aarch64.rpm",
        "emacs-nox-27.2-9.oe2203sp1.aarch64.rpm"
    ],
    "x86_64": [
        "emacs-common-27.2-9.oe2203sp1.x86_64.rpm",
        "emacs-debugsource-27.2-9.oe2203sp1.x86_64.rpm",
        "emacs-devel-27.2-9.oe2203sp1.x86_64.rpm",
        "emacs-lucid-27.2-9.oe2203sp1.x86_64.rpm",
        "emacs-27.2-9.oe2203sp1.x86_64.rpm",
        "emacs-debuginfo-27.2-9.oe2203sp1.x86_64.rpm",
        "emacs-nox-27.2-9.oe2203sp1.x86_64.rpm"
    ]
}