OS Command Injection in Emacs - CVE-2022-45939
Published: December 1, 2022 / Updated: February 26, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation when processing name of a source-code file in lib-src/etags.c. A remote attacker can trick the victim to use the "ctags *" command and execute arbitrary OS commands on the target system in a situation where the current working directory has contents that depend on untrusted input.
Affected software
Amazon Linux AMI
Debian Linux
Oracle Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Anolis OS
Fedora
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
emacs24-el (Ubuntu package)
emacs-bin-common (Ubuntu package)
emacs (Ubuntu package)
emacs-common (Ubuntu package)
emacs24 (Ubuntu package)
emacs24-bin-common (Ubuntu package)
emacs-el (Ubuntu package)
emacs25 (Ubuntu package)
emacs25-bin-common (Ubuntu package)
emacs25-common (Ubuntu package)
emacs25-el (Ubuntu package)
emacs24-common (Ubuntu package)
emacs
etags
etags-debuginfo
emacs-x11-debuginfo
emacs-x11
emacs-nox-debuginfo
emacs-nox
emacs-debugsource
emacs-debuginfo
emacs-info
emacs-el
emacs (Red Hat package)
emacs (Debian package)
emacs-lucid
emacs-terminal
emacs-help
emacs-filesystem
emacs-common
emacs-devel
emacs-doc
IBM Cloud Pak for Watson AIOps
EMC Cloud Tiering Appliance
How to mitigate CVE-2022-45939
emacs24-el (Ubuntu package) - update to Ubuntu Pro
emacs-bin-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs24 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs24-bin-common (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs-el (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs25 (Ubuntu package) - update to Ubuntu Pro
emacs25-bin-common (Ubuntu package) - update to Ubuntu Pro
emacs25-common (Ubuntu package) - update to Ubuntu Pro
emacs25-el (Ubuntu package) - update to Ubuntu Pro
emacs24-common (Ubuntu package) - update to Ubuntu Pro
IBM Cloud Pak for Watson AIOps - update to 4.2.0
EMC Cloud Tiering Appliance - update to 13.1.0.2.29
emacs - addressed in versions 24.3-20.25, 28.1-2, 28.2-3
etags - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
etags-debuginfo - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-x11-debuginfo - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-x11 - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-nox-debuginfo - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-nox - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-debugsource - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-debuginfo - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-info - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-el - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs (Red Hat package) - addressed in versions 26.1-9.el8, 27.2-8.el9
emacs (Debian package) - update to 1:27.1+1-3.1+deb11u1
emacs-nox - update to 27.1-9
emacs-debuginfo - update to 27.1-9
emacs-lucid - update to 27.1-9
emacs-terminal - update to 27.1-9
emacs-help - update to 27.1-9
emacs-filesystem - update to 27.1-9
emacs-common - update to 27.1-9
emacs-debugsource - update to 27.1-9
emacs-devel - update to 27.1-9
emacs - update to 27.1-9
emacs - addressed in versions 27.2, 29.3
emacs - addressed in versions 28.2-1.fc36, 28.2-1.fc37, 28.2-1.fc38
emacs - update to 29.1-1
emacs-common - update to 29.1-1
emacs-devel - update to 29.1-1
emacs-lucid - update to 29.1-1
emacs-nox - update to 29.1-1
emacs-doc - update to 29.1-1
emacs-filesystem - update to 29.1-1
emacs-terminal - update to 29.1-1
External References
Related Security Bulletins
- OS command injection in GNU Emacs
- SUSE update for emacs
- SUSE update for emacs
- SUSE update for emacs
- Slackware Linux update for emacs
- Ubuntu update for emacs24
- Debian update for emacs
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Oracle Solaris
- Amazon Linux AMI update for emacs
- Red Hat Enterprise Linux 9 update for emacs
- Red Hat Enterprise Linux 8 update for emacs
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- openEuler update for emacs
- Red Hat Enterprise Linux 8.6 Extended Update Support update for emacs
- Slackware Linux update for emacs
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Amazon Linux AMI update for emacs
- Amazon Linux AMI update for emacs
- Ubuntu update for emacs
- Fedora 38 update for emacs
- Fedora 36 update for emacs
- Fedora 37 update for emacs
- Anolis OS update for emacs