Lack of data validation In emacs
Description
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | 1:27.1+1-3.1+deb11u5 | ||
debian 11 | 9.4.0+dfsg-1+deb11u3 | ||
debian 12 | 1:28.2+1-15+deb12u3 | ||
debian 12 | - | ||
debian 13 | 1:29.4+1-1 | ||
debian 13 | 9.7.5+dfsg-1 | ||
debian 14 | 1:29.4+1-1 | ||
debian 14 | 9.7.5+dfsg-1 | ||
rpm rhel9 | 1:27.2-10.el9_4 | ||
rpm rhel6 | - | - |
1-10 of 14
10
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5. 6.