Univention Bugzilla – Bug 56063
emacs: Multiple issues (5.0)
Last modified: 2023-05-17 12:54:24 CEST
New Debian emacs 1:26.1+1-3.2+deb10u4 fixes: This update addresses the following issues: * command execution via shell metacharacters (CVE-2022-48337) * command injection vulnerability in htmlfontify.el (CVE-2022-48339) * command injection vulnerability in org-mode (CVE-2023-28617)
--- mirror/ftp/pool/main/e/emacs/emacs_26.1+1-3.2+deb10u3.dsc +++ apt/ucs_5.0-0-errata5.0-3/source/emacs_26.1+1-3.2+deb10u4.dsc @@ -1,3 +1,10 @@ +1:26.1+1-3.2+deb10u4 [Tue, 09 May 2023 23:36:16 +0200] Markus Koschany <apo@debian.org>: + + * Non-maintainer upload by the LTS team. + * Fix CVE-2022-48337, CVE-2022-48339 and CVE-2023-28617: + Xi Lu discovered that missing input sanitising in Emacs could result in the + execution of arbitrary shell commands. + 1:26.1+1-3.2+deb10u3 [Sat, 31 Dec 2022 12:40:43 +0000] Chris Lamb <lamby@debian.org>: * Non-maintainer upload by the Debian LTS team. <http://piuparts.knut.univention.de/5.0-3/#6800914901534503173>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.0-3] 1c6770509e Bug #56063: emacs 1:26.1+1-3.2+deb10u4 doc/errata/staging/emacs.yaml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) [5.0-3] 5ea264dc90 Bug #56063: emacs 1:26.1+1-3.2+deb10u4 doc/errata/staging/emacs.yaml | 16 ++++++++++++++++ 1 file changed, 16 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.0x665>