[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2023-2023-134 --- emacs

ID: oval:org.secpod.oval:def:19500207Date: (C)2023-06-12   (M)2024-01-03
Class: PATCHFamily: unix




emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters

Platform:
Amazon Linux 2023
Product:
emacs
Reference:
ALAS2023-2023-134
CVE-2023-27985
CVE-2023-27986
CVE    2
CVE-2023-27985
CVE-2023-27986
CPE    1
cpe:/a:gnu:emacs

© SecPod Technologies