OS Command Injection in Emacs - CVE-2022-48339
Published: February 26, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within the hfy-istext-command() function when parsing the "file" and "srcdir" parameters, if a file name or directory name contains shell metacharacter. A remote attacker can execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Operational Decision Manager
Debian Linux
Amazon Linux AMI
Oracle Linux
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Retail Branch Server
Red Hat Enterprise Linux Server
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Anolis OS
Red Hat Enterprise Linux Workstation
SUSE Enterprise Storage
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Oracle Solaris
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
Desktop Applications Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Red Hat OpenShift Builds
Migration Toolkit for Runtimes
OpenShift Pipelines
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Netcool Operations Insight
Red Hat OpenShift Dev Spaces
IBM Cloud Pak for Business Automation
IBM Automation Decision Services
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat OpenShift GitOps
IBM QRadar Network Packet Capture
OpenShift Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
emacs24-el (Ubuntu package)
emacs24 (Ubuntu package)
emacs (Ubuntu package)
emacs-bin-common (Ubuntu package)
emacs-common (Ubuntu package)
emacs-el (Ubuntu package)
emacs25 (Ubuntu package)
emacs25-bin-common (Ubuntu package)
emacs25-common (Ubuntu package)
emacs25-el (Ubuntu package)
emacs24-bin-common (Ubuntu package)
emacs24-common (Ubuntu package)
app-editors/emacs
emacs
emacs-common
emacs-terminal
emacs-filesystem
emacs-el
emacs-nox
emacs (Red Hat package)
emacs-x11-debuginfo
emacs-info
emacs-debuginfo
emacs-debugsource
etags
etags-debuginfo
emacs-x11
emacs-nox-debuginfo
emacs (Debian package)
emacs-help
emacs-devel
emacs-lucid
emacs-doc
Storage Defender – Data Protect
IBM Cloud Pak for Watson AIOps
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
XtremIO X2
How to mitigate CVE-2022-48339
Migration Toolkit for Runtimes - update to 1.2.4
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
Red Hat OpenShift GitOps - update to 1.9.3
OpenShift Pipelines - update to 1.10.6
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.74.8, 4.1.6, 4.3.1
Red Hat OpenShift Container Platform - addressed in versions 4.11.59, 4.13.2, 4.13.45, 4.14.32, 4.14.33, 4.15.3
OpenShift Virtualization - update to 4.12.9
OpenShift Logging - update to 5.7.10
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
emacs24-el (Ubuntu package) - update to Ubuntu Pro
emacs24 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-bin-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-el (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs25 (Ubuntu package) - update to Ubuntu Pro
emacs25-bin-common (Ubuntu package) - update to Ubuntu Pro
emacs25-common (Ubuntu package) - update to Ubuntu Pro
emacs25-el (Ubuntu package) - update to Ubuntu Pro
emacs24-bin-common (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs24-common (Ubuntu package) - update to Ubuntu Pro
Storage Defender – Data Protect - update to 1.3.0
Netcool Operations Insight - update to 1.6.12
Red Hat OpenShift Dev Spaces - update to 3.15.0
IBM Cloud Pak for Watson AIOps - update to 4.4.0
DB2 on Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
XtremIO X2 - update to 6.4.2-13
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 7
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 49, 8.11.0.1 Interim fix 26, 8.12.0 Interim fix 8
app-editors/emacs - update to 9.6.23
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.28, 23.0.1.6
IBM Automation Decision Services - update to 23.0.1 IF006
emacs - addressed in versions 24.3-20.25, 28.2-3
emacs - addressed in versions 24.3-23, 27.2-8.0.2, 29.1-1
emacs-common - addressed in versions 24.3-23, 27.2-8.0.2, 29.1-1
emacs-terminal - addressed in versions 24.3-23, 27.2-8.0.2, 29.1-1
emacs-filesystem - addressed in versions 24.3-23, 27.2-8.0.2, 29.1-1
emacs-el - update to 24.3-23
emacs-nox - addressed in versions 24.3-23, 27.2-8.0.2, 29.1-1
emacs (Red Hat package) - addressed in versions 24.3-23.el7_9.1, 26.1-10.el8_8.4, 26.1-11.el8, 27.2-8.el9_2.1
emacs-x11-debuginfo - addressed in versions 24.3-25.12.1, 25.3-150000.3.15.1, 27.2-150400.3.6.1
emacs-info - addressed in versions 24.3-25.12.1, 25.3-150000.3.15.1, 27.2-150400.3.6.1
emacs-el - addressed in versions 24.3-25.12.1, 25.3-150000.3.15.1, 27.2-150400.3.6.1
emacs-debuginfo - addressed in versions 24.3-25.12.1, 25.3-150000.3.15.1, 27.2-150400.3.6.1
emacs-nox - addressed in versions 24.3-25.12.1, 25.3-150000.3.15.1, 27.2-150400.3.6.1
emacs - addressed in versions 24.3-25.12.1, 25.3-150000.3.15.1, 27.2-150400.3.6.1
emacs-debugsource - addressed in versions 24.3-25.12.1, 25.3-150000.3.15.1, 27.2-150400.3.6.1
etags - addressed in versions 24.3-25.12.1, 25.3-150000.3.15.1, 27.2-150400.3.6.1
etags-debuginfo - addressed in versions 24.3-25.12.1, 25.3-150000.3.15.1, 27.2-150400.3.6.1
emacs-x11 - addressed in versions 24.3-25.12.1, 25.3-150000.3.15.1, 27.2-150400.3.6.1
emacs-nox-debuginfo - addressed in versions 24.3-25.12.1, 25.3-150000.3.15.1, 27.2-150400.3.6.1
emacs (Debian package) - update to 1:27.1+1-3.1+deb11u2
emacs-filesystem - update to 27.1-10
emacs-terminal - update to 27.1-10
emacs - update to 27.1-10
emacs-help - update to 27.1-10
emacs-debuginfo - update to 27.1-10
emacs-nox - update to 27.1-10
emacs-debugsource - update to 27.1-10
emacs-common - update to 27.1-10
emacs-devel - update to 27.1-10
emacs-lucid - update to 27.1-10
emacs-lucid - addressed in versions 27.2-8.0.2, 29.1-1
emacs - addressed in versions 28.3-0.rc1.fc37, 28.3-0.rc1.fc38
emacs-devel - update to 29.1-1
emacs-doc - update to 29.1-1
External References
Related Security Bulletins
- OS command injection in GNU Emacs
- Debian update for emacs
- SUSE update for emacs
- SUSE update for emacs
- SUSE update for emacs
- Ubuntu update for emacs24
- Amazon Linux AMI update for emacs
- Red Hat Enterprise Linux 9 update for emacs
- Multiple vulnerabilities in Oracle Linux
- Red Hat Enterprise Linux 7 update for emacs
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- CentOS 7 update for emacs
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in IBM Storage Defender Data Protect
- Fedora 38 update for emacs
- Fedora 37 update for emacs
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat OpenShift Container Platform release 4.13
- Red Hat Enterprise Linux 8 update for emacs
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.9
- Multiple vulnerabilities in Red Hat OpenShift Pipelines 1.10
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.3
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in IBM Automation Decision Services
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- Multiple vulnerabilities in Logging Subsystem 5.7 for Red Hat OpenShift
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.74
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 4.1
- Multiple vulnerabilities in Migration Toolkit for Runtimes 1.2
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM QRadar Network Packet Capture
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- openEuler update for emacs
- Red Hat Enterprise Linux 8.6 Extended Update Support update for emacs
- Red Hat Enterprise Linux 8.8 Extended Update Support update for emacs
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.11
- Multiple vulnerabilities in Netcool Operations Insight
- Multiple vulnerabilities in Red Hat OpenShift Builds
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.7
- Gentoo update for GNU Emacs, Org Mode
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Amazon Linux AMI update for emacs
- Ubuntu update for emacs
- Multiple vulnerabilities in Dell XtremIO X2
- Anolis OS update for emacs
- Anolis OS update for emacs
- Anolis OS update for emacs