ZeroHour

CVE-2023-2491

CVSS 3.1
7.8 high
EPSS
<1%p39
Published
()
Modified
Description

A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.

Vendors
gnuredhat
Products
emacs, enterprise linux, enterprise linux eus, enterprise linux server aus, enterprise linux server tus
Weakness
CWE-77
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.