CVE-2017-14482
published 2017-09-14CVE-2017-14482: GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML…
PriorityP350high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
4.01%
89.4th percentile
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| gnu | emacs | <= 25.2 | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2v7h-5r83-vh8r: GNU Emacs before 25
ghsa_unreviewed·2022-05-13
CVE-2017-14482 [HIGH] GHSA-2v7h-5r83-vh8r: GNU Emacs before 25
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).
OSV
CVE-2017-14482: GNU Emacs before 25
osv·2017-09-14·CVSS 8.8
CVE-2017-14482 [HIGH] CVE-2017-14482: GNU Emacs before 25
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).
Ubuntu
Emacs vulnerability
vendor_ubuntu·2017-09-21
CVE-2017-14482 Emacs vulnerability
Title: Emacs vulnerability
Summary: Emacs could be made to run programs as your login if it
opened a specially crafted file.
Charles A. Roelli discovered that Emacs incorrectly handled certain
files. If a user were tricked into opening a specially crafted file (e.g., email
messages in gnus), an attacker could possibly use this to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Emacs vulnerability
vendor_ubuntu·2017-09-21
CVE-2017-14482 Emacs vulnerability
Title: Emacs vulnerability
Summary: Emacs could be made to run programs as your login if it opened a specially crafted file.
Charles A. Roelli discovered that Emacs incorrectly handled certain
files. If a user were tricked into opening a specially crafted file (e.g., email
messages in gnus), an attacker could possibly use this to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
emacs: command injection flaw within "enriched mode" handling
vendor_redhat·2017-09-04·CVSS 8.8
CVE-2017-14482 [HIGH] CWE-20 emacs: command injection flaw within "enriched mode" handling
emacs: command injection flaw within "enriched mode" handling
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).
A command injection flaw within the Emacs "enriched mode" handling has been discovered. By tricking an unsuspecting user into opening a specially crafted file using Emacs, a remote attacker could exploit this flaw to execute arbitrary c
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-14482 emacs: Unsafe enriched mode translations [fedora-all]
bugzilla·2017-09-11·CVSS 8.8
CVE-2017-14482 [HIGH] CVE-2017-14482 emacs: Unsafe enriched mode translations [fedora-all]
CVE-2017-14482 emacs: Unsafe enriched mode translations [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedor
Bugzilla
CVE-2017-14482 emacs: command injection flaw within "enriched mode" handling
bugzilla·2017-09-11·CVSS 8.8
CVE-2017-14482 [HIGH] CVE-2017-14482 emacs: command injection flaw within "enriched mode" handling
CVE-2017-14482 emacs: command injection flaw within "enriched mode" handling
Enriched mode implements an extension command to the text/enriched format called "x-display", which stores "display" text properties. It's possible to use this extension command to transparently execute arbitrary code in an Emacs process that opens a text/enriched file.
Upstream issue:
https://debbugs.gnu.org/cgi/bugreport.cgi?bug=28350
Upstream patch:
https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-25&id=9ad0fcc54442a9a01d41be19880250783426db70
References:
http://seclists.org/oss-sec/2017/q3/422
Discussion:
Created emacs tracking bugs for this issue:
Affects: fedora-all [bug 1490410]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2017:277
http://www.debian.org/security/2017/dsa-3975http://www.openwall.com/lists/oss-security/2017/09/11/1https://access.redhat.com/errata/RHSA-2017:2771https://debbugs.gnu.org/cgi/bugreport.cgi?bug=28350https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-25&id=9ad0fcc54442a9a01d41be19880250783426db70https://security.gentoo.org/glsa/201801-07https://www.debian.org/security/2017/dsa-3970https://www.gnu.org/software/emacs/index.html#Releaseshttp://www.debian.org/security/2017/dsa-3975http://www.openwall.com/lists/oss-security/2017/09/11/1https://access.redhat.com/errata/RHSA-2017:2771https://debbugs.gnu.org/cgi/bugreport.cgi?bug=28350https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-25&id=9ad0fcc54442a9a01d41be19880250783426db70https://security.gentoo.org/glsa/201801-07https://www.debian.org/security/2017/dsa-3970https://www.gnu.org/software/emacs/index.html#Releases
2017-09-14
Published