CVE-2024-30204
published 2024-03-25CVE-2024-30204: In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
PriorityP410low2.8CVSS 3.1
AVLACLPRLUIRSUCNINAL
EPSS
0.47%
37.6th percentile
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | emacs | < emacs 1:28.2+1-15+deb12u1 (bookworm) | emacs 1:28.2+1-15+deb12u1 (bookworm) |
| debian | org-mode | < emacs 1:28.2+1-15+deb12u1 (bookworm) | emacs 1:28.2+1-15+deb12u1 (bookworm) |
| gnu | emacs | < 29.3 | 29.3 |
| gnu | emacs | >= 0 < 1:27.1+1-3.1+deb11u3 | 1:27.1+1-3.1+deb11u3 |
| gnu | emacs | >= 0 < 1:28.2+1-15+deb12u1 | 1:28.2+1-15+deb12u1 |
| gnu | emacs | >= 0 < 1:29.3+1-1 | 1:29.3+1-1 |
| gnu | emacs | >= 0 < 1:29.3+1-1 | 1:29.3+1-1 |
| gnu | emacs | >= 0 < 1:27.1+1-3ubuntu5.2 | 1:27.1+1-3ubuntu5.2 |
| gnu | emacs | >= 0 < 1:26.3+1-1ubuntu2+esm1 | 1:26.3+1-1ubuntu2+esm1 |
| gnu | emacs | >= 0 < 1:29.3+1-1ubuntu2+esm1 | 1:29.3+1-1ubuntu2+esm1 |
| gnu | org_mode | < 9.6.23 | 9.6.23 |
| msrc | azl3_emacs_29.3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_emacs_29.4-3_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.12.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.5MEDIUM
vendor_debian2.8LOW
vendor_msrc2.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Emacs vulnerabilities
vendor_ubuntu·2024-09-19·CVSS 7.8
CVE-2024-39331 [HIGH] Emacs vulnerabilities
Title: Emacs vulnerabilities
Summary: Several security issues were fixed in Emacs.
It was discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. (CVE-2022-45939)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS. (CVE-2022-48337)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 22.04 LTS. (CVE-2022-48338)
Xi Lu discov
Red Hat
emacs: LaTeX preview is enabled by default for e-mail attachments
vendor_redhat·2024-03-25·CVSS 2.8
CVE-2024-30204 [LOW] CWE-349 emacs: LaTeX preview is enabled by default for e-mail attachments
emacs: LaTeX preview is enabled by default for e-mail attachments
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
A flaw was found in Emacs. When Emacs is used as an email client, a preview of a crafted LaTeX document attached to an email can exhaust the disk space or the inodes allocated for the partition where the /tmp directory is located. This issue possibly results in a denial of service.
Mitigation: Do not open or do not generate a preview of LaTeX documents from untrusted sources.
Package: emacs (Red Hat Enterprise Linux 10) - Affected
Package: emacs (Red Hat Enterprise Linux 6) - Out of support scope
Package: emacs (Red Hat Enterprise Linux 7) - Out of support scope
Package: emacs (Red Hat Enterprise Linux 8) - Affected
Red Hat
emacs: Gnus treats inline MIME contents as trusted
vendor_redhat·2024-03-25·CVSS 5.5
CVE-2024-30203 [MEDIUM] CWE-349 emacs: Gnus treats inline MIME contents as trusted
emacs: Gnus treats inline MIME contents as trusted
In Emacs before 29.3, Gnus treats inline MIME contents as trusted.
A flaw was found in Emacs. When Emacs is used as an email client, inline MIME attachments are considered to be trusted by default, allowing a crafted LaTeX document to exhaust the disk space or the inodes allocated for the partition where the /tmp directory is located. This issue possibly results in a denial of service.
Statement: This issue is very similar to CVE-2024-30204. See https://access.redhat.com/security/cve/CVE-2024-30204.
Mitigation: Do not open emails from untrusted sources.
Package: emacs (Red Hat Enterprise Linux 10) - Affected
Package: emacs (Red Hat Enterprise Linux 6) - Out of support scope
Package: emacs (Red Hat Enterprise Linux 7) - Out of suppor
Microsoft
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
vendor_msrc·2024-03-12·CVSS 2.8
CVE-2024-30204 [LOW] CWE-276 In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Debian
CVE-2024-30204: emacs - In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments...
vendor_debian·2024·CVSS 2.8
CVE-2024-30204 [LOW] CVE-2024-30204: emacs - In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments...
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
Scope: local
bookworm: resolved (fixed in 1:28.2+1-15+deb12u1)
bullseye: resolved (fixed in 1:27.1+1-3.1+deb11u3)
forky: resolved (fixed in 1:29.3+1-1)
sid: resolved (fixed in 1:29.3+1-1)
trixie: resolved (fixed in 1:29.3+1-1)
OSV
emacs, emacs24, emacs25 vulnerabilities
osv·2024-09-19·CVSS 7.8
CVE-2022-45939 [HIGH] emacs, emacs24, emacs25 vulnerabilities
emacs, emacs24, emacs25 vulnerabilities
It was discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04
LTS. (CVE-2022-45939)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS. (CVE-2022-48337)
Xi Lu discovered that Emacs incorrectly handled input sanitization. An
attacker could possibly use this issue to execute arbitrary commands. This
issue only affected Ubuntu 22.04 LTS. (CVE-2022-48338)
Xi Lu discovered that Emacs incorrectly handled input sa
GHSA
GHSA-27fr-v43j-r34m: In Emacs before 29
ghsa_unreviewed·2024-03-25
CVE-2024-30204 [LOW] CWE-276 GHSA-27fr-v43j-r34m: In Emacs before 29
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
OSV
CVE-2024-30204: In Emacs before 29
osv·2024-03-25·CVSS 2.8
CVE-2024-30204 [LOW] CVE-2024-30204: In Emacs before 29
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2024/03/25/2http://www.openwall.com/lists/oss-security/2024/04/08/3http://www.openwall.com/lists/oss-security/2024/04/08/4http://www.openwall.com/lists/oss-security/2024/04/08/6http://www.openwall.com/lists/oss-security/2024/04/08/7http://www.openwall.com/lists/oss-security/2024/04/10/3http://www.openwall.com/lists/oss-security/2024/04/10/4http://www.openwall.com/lists/oss-security/2024/04/10/5http://www.openwall.com/lists/oss-security/2024/04/10/6http://www.openwall.com/lists/oss-security/2024/04/11/4https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=6f9ea396f49cbe38c2173e0a72ba6af3e03b271chttps://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29https://lists.debian.org/debian-lts-announce/2024/04/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2024/04/msg00024.htmlhttp://www.openwall.com/lists/oss-security/2024/03/25/2http://www.openwall.com/lists/oss-security/2024/04/08/3http://www.openwall.com/lists/oss-security/2024/04/08/4http://www.openwall.com/lists/oss-security/2024/04/08/6http://www.openwall.com/lists/oss-security/2024/04/08/7http://www.openwall.com/lists/oss-security/2024/04/10/3http://www.openwall.com/lists/oss-security/2024/04/10/4http://www.openwall.com/lists/oss-security/2024/04/10/5http://www.openwall.com/lists/oss-security/2024/04/10/6http://www.openwall.com/lists/oss-security/2024/04/11/4https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=6f9ea396f49cbe38c2173e0a72ba6af3e03b271chttps://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29https://lists.debian.org/debian-lts-announce/2024/04/msg00023.htmlhttps://lists.debian.org/debian-lts-announce/2024/04/msg00024.html
2024-03-25
Published