CVE-2023-2491
published 2023-05-17CVE-2023-2491: A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result…
PriorityP345high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.46%
37.1th percentile
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_debian7.8LOW
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
emacs: Regression of CVE-2023-28617 fixes in the Red Hat Enterprise Linux
vendor_redhat·2023-05-09·CVSS 7.8
CVE-2023-2491 [HIGH] CWE-77 emacs: Regression of CVE-2023-28617 fixes in the Red Hat Enterprise Linux
emacs: Regression of CVE-2023-28617 fixes in the Red Hat Enterprise Linux
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Statement: This issue only affects Red
Debian
CVE-2023-2491: emacs - A flaw was found in the Emacs text editor. Processing a specially crafted org-mo...
vendor_debian·2023·CVSS 7.8
CVE-2023-2491 [HIGH] CVE-2023-2491: emacs - A flaw was found in the Emacs text editor. Processing a specially crafted org-mo...
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-2hj6-9wp7-hvmh: A flaw was found in the Emacs text editor
ghsa_unreviewed·2023-05-18·CVSS 7.8
CVE-2023-2491 [HIGH] CWE-77 GHSA-2hj6-9wp7-hvmh: A flaw was found in the Emacs text editor
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:2626https://access.redhat.com/errata/RHSA-2023:3104https://access.redhat.com/security/cve/CVE-2023-2491https://bugzilla.redhat.com/show_bug.cgi?id=2192873https://access.redhat.com/errata/RHSA-2023:2626https://access.redhat.com/errata/RHSA-2023:3104https://access.redhat.com/security/cve/CVE-2023-2491https://bugzilla.redhat.com/show_bug.cgi?id=2192873
2023-05-17
Published