CVE-2022-48338
published 2023-02-20CVE-2022-48338: An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The…
PriorityP340high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
1.64%
73.7th percentile
An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | emacs | < emacs 1:28.2+1-11 (bookworm) | emacs 1:28.2+1-11 (bookworm) |
| gnu | emacs | <= 28.2 | — |
| gnu | emacs | >= 0 < 1:27.1+1-3.1+deb11u2 | 1:27.1+1-3.1+deb11u2 |
| gnu | emacs | >= 0 < 1:28.2+1-11 | 1:28.2+1-11 |
| gnu | emacs | >= 0 < 1:28.2+1-11 | 1:28.2+1-11 |
| gnu | emacs | >= 0 < 1:28.2+1-11 | 1:28.2+1-11 |
| gnu | emacs | >= 0 < 1:27.1+1-3ubuntu5.2 | 1:27.1+1-3ubuntu5.2 |
| gnu | emacs | >= 0 < 1:26.3+1-1ubuntu2+esm1 | 1:26.3+1-1ubuntu2+esm1 |
| gnu | emacs | >= 0 < 1:29.3+1-1ubuntu2+esm1 | 1:29.3+1-1ubuntu2+esm1 |
| msrc | cbl2_emacs_28.2-4_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian7.3HIGH
vendor_msrc7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Emacs vulnerabilities
vendor_ubuntu·2024-09-19·CVSS 7.8
CVE-2024-39331 [HIGH] Emacs vulnerabilities
Title: Emacs vulnerabilities
Summary: Several security issues were fixed in Emacs.
It was discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. (CVE-2022-45939)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS. (CVE-2022-48337)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 22.04 LTS. (CVE-2022-48338)
Xi Lu discov
Red Hat
emacs: local command injection in ruby-mode.el
vendor_redhat·2023-02-21·CVSS 7.3
CVE-2022-48338 [HIGH] CWE-77 emacs: local command injection in ruby-mode.el
emacs: local command injection in ruby-mode.el
An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.
A flaw was found in the Emacs package. A malicious ruby source file may cause a local command injection.
Statement: This vulnerability is only triggered when a local user runs Emacs with untrusted input. For this reason, this flaw has been rated with a Moderate security impact.
Package: emacs (Red Hat Ente
Microsoft
An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactiv
vendor_msrc·2023-02-14·CVSS 7.3
CVE-2022-48338 [HIGH] CWE-77 An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactiv
An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function and bound to C-c C-f. Inside the function the external command gem is called through shell-command-to-string but the feature-name parameters are not escaped. Thus malicious Ruby source files may cause commands to be executed.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the di
Debian
CVE-2022-48338: emacs - An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-fin...
vendor_debian·2022·CVSS 7.3
CVE-2022-48338 [HIGH] CVE-2022-48338: emacs - An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-fin...
An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.
Scope: local
bookworm: resolved (fixed in 1:28.2+1-11)
bullseye: resolved (fixed in 1:27.1+1-3.1+deb11u2)
forky: resolved (fixed in 1:28.2+1-11)
sid: resolved (fixed in 1:28.2+1-11)
trixie: resolved (fixed in 1:28.2+1-11)
OSV
emacs, emacs24, emacs25 vulnerabilities
osv·2024-09-19·CVSS 7.8
CVE-2022-45939 [HIGH] emacs, emacs24, emacs25 vulnerabilities
emacs, emacs24, emacs25 vulnerabilities
It was discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. (CVE-2022-45939)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS. (CVE-2022-48337)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 22.04 LTS. (CVE-2022-48338)
Xi Lu discovered that Emacs incorrectly handled input sa
GHSA
GHSA-hm6m-2xg8-mc5q: An issue was discovered in GNU Emacs through 28
ghsa_unreviewed·2023-02-21
CVE-2022-48338 [CRITICAL] CWE-77 GHSA-hm6m-2xg8-mc5q: An issue was discovered in GNU Emacs through 28
An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.
OSV
CVE-2022-48338: An issue was discovered in GNU Emacs through 28
osv·2023-02-20·CVSS 7.3
CVE-2022-48338 [HIGH] CVE-2022-48338: An issue was discovered in GNU Emacs through 28
An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through shell-command-to-string, but the feature-name parameters are not escaped. Thus, malicious Ruby source files may cause commands to be executed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://git.savannah.gnu.org/cgit/emacs.git/commit/?id=9a3b08061feea14d6f37685ca1ab8801758bfd1chttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FLPQ4K6H2S5TY3L5UDN4K4B3L5RQJYQ6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6HDBUQNAH2WL4MHWCTUZLN7NGF7CHTK/https://www.debian.org/security/2023/dsa-5360https://git.savannah.gnu.org/cgit/emacs.git/commit/?id=9a3b08061feea14d6f37685ca1ab8801758bfd1chttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FLPQ4K6H2S5TY3L5UDN4K4B3L5RQJYQ6/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U6HDBUQNAH2WL4MHWCTUZLN7NGF7CHTK/https://www.debian.org/security/2023/dsa-5360
2023-02-20
Published