CVE-2024-39331
23.06.2024, 22:15
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
| Vendor | Product | Version |
|---|---|---|
| gnu | emacs | 𝑥 < 29.4 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| emacs |
| ||||||||||||||
| org-mode |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| emacs |
| ||||||||||||||||||
| xemacs21 |
| ||||||||||||||||||
| xemacs21-packages |
| ||||||||||||||||||
| emacs24 |
| ||||||||||||||||||
| emacs25 |
| ||||||||||||||||||
| org-mode |
|
References