CVE-2023-27985
09.03.2023, 06:15
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90
| Vendor | Product | Version |
|---|---|---|
| gnu | emacs | 28.1 ≤ 𝑥 ≤ 28.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| emacs |
| ||||||||||||||||||||
| emacs23 |
| ||||||||||||||||||||
| emacs24 |
| ||||||||||||||||||||
| emacs25 |
| ||||||||||||||||||||
| xemacs21 |
| ||||||||||||||||||||
| xemacs21-packages |
|
References