OS Command Injection in Emacs - CVE-2022-45939

 

OS Command Injection in Emacs - CVE-2022-45939

Published: December 1, 2022 / Updated: February 26, 2023


Vulnerability identifier: #VU69808
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-45939
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation when processing name of a source-code file in lib-src/etags.c. A remote attacker can trick the victim to use the "ctags *" command  and execute arbitrary OS commands on the target system in a situation where the current working directory has contents that depend on untrusted input.



Affected software

Emacs
Amazon Linux AMI
Debian Linux
Oracle Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Desktop Applications
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Anolis OS
Fedora
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
emacs24-el (Ubuntu package)
emacs-bin-common (Ubuntu package)
emacs (Ubuntu package)
emacs-common (Ubuntu package)
emacs24 (Ubuntu package)
emacs24-bin-common (Ubuntu package)
emacs-el (Ubuntu package)
emacs25 (Ubuntu package)
emacs25-bin-common (Ubuntu package)
emacs25-common (Ubuntu package)
emacs25-el (Ubuntu package)
emacs24-common (Ubuntu package)
emacs
etags
etags-debuginfo
emacs-x11-debuginfo
emacs-x11
emacs-nox-debuginfo
emacs-nox
emacs-debugsource
emacs-debuginfo
emacs-info
emacs-el
emacs (Red Hat package)
emacs (Debian package)
emacs-lucid
emacs-terminal
emacs-help
emacs-filesystem
emacs-common
emacs-devel
emacs-doc
IBM Cloud Pak for Watson AIOps
EMC Cloud Tiering Appliance

How to mitigate CVE-2022-45939

Install update from vendor's website.

Red Hat OpenShift Container Platform - addressed in versions 4.11.59, 4.15.3
emacs24-el (Ubuntu package) - update to Ubuntu Pro
emacs-bin-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs24 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs24-bin-common (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs-el (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs25 (Ubuntu package) - update to Ubuntu Pro
emacs25-bin-common (Ubuntu package) - update to Ubuntu Pro
emacs25-common (Ubuntu package) - update to Ubuntu Pro
emacs25-el (Ubuntu package) - update to Ubuntu Pro
emacs24-common (Ubuntu package) - update to Ubuntu Pro
IBM Cloud Pak for Watson AIOps - update to 4.2.0
EMC Cloud Tiering Appliance - update to 13.1.0.2.29
emacs - addressed in versions 24.3-20.25, 28.1-2, 28.2-3
etags - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
etags-debuginfo - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-x11-debuginfo - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-x11 - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-nox-debuginfo - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-nox - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-debugsource - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-debuginfo - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-info - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs-el - addressed in versions 24.3-25.9.1, 25.3-150000.3.12.1, 27.2-150400.3.3.1
emacs (Red Hat package) - addressed in versions 26.1-9.el8, 27.2-8.el9
emacs (Debian package) - update to 1:27.1+1-3.1+deb11u1
emacs-nox - update to 27.1-9
emacs-debuginfo - update to 27.1-9
emacs-lucid - update to 27.1-9
emacs-terminal - update to 27.1-9
emacs-help - update to 27.1-9
emacs-filesystem - update to 27.1-9
emacs-common - update to 27.1-9
emacs-debugsource - update to 27.1-9
emacs-devel - update to 27.1-9
emacs - update to 27.1-9
emacs - addressed in versions 27.2, 29.3
emacs - addressed in versions 28.2-1.fc36, 28.2-1.fc37, 28.2-1.fc38
emacs - update to 29.1-1
emacs-common - update to 29.1-1
emacs-devel - update to 29.1-1
emacs-lucid - update to 29.1-1
emacs-nox - update to 29.1-1
emacs-doc - update to 29.1-1
emacs-filesystem - update to 29.1-1
emacs-terminal - update to 29.1-1

External References

Related Security Bulletins