CVE-2024-39331
23.06.2024, 22:15
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
Vendor | Product | Version |
---|---|---|
gnu | emacs | 𝑥 < 29.4 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
emacs |
| ||||||||||||
org-mode |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
emacs |
| ||||||||||||||||
emacs24 |
| ||||||||||||||||
emacs25 |
| ||||||||||||||||
org-mode |
| ||||||||||||||||
xemacs21 |
| ||||||||||||||||
xemacs21-packages |
|
References