Server side template injection In emacs
Description
A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a specially crafted website or an HTTP URL with a redirect.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 14 | 1:30.1+1-1 | ||
debian 12 | 1:28.2+1-15+deb12u4 | ||
debian 13 | 1:30.1+1-1 | ||
debian 11 | 1:27.1+1-3.1+deb11u6 | ||
rpm rhel6 | - | - | |
rpm rhel8.8 | 1:26.1-10.el8_8.7 | ||
rpm rhel8 | 1:26.1-13.el8_10 | ||
rpm rhel7 | - | - | |
rpm rhel9 | 1:27.2-11.el9_5.1 | ||
rpm rhel9.2 | 1:27.2-8.el9_2.2 |
1-10 of 11
10
Aliases
1. 2. 3. 4. 5.