OS Command Injection in Org Mode - CVE-2023-28617
Published: April 6, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation within the org-babel-execute:latex in ob-latex.el when processing file or directory names. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary OS commands on the target system via a file name or directory name that contains shell metacharacters.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Amazon Linux AMI
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Ubuntu
openEuler
Migration Toolkit for Runtimes
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
emacs24-common (Ubuntu package)
emacs-common (Ubuntu package)
emacs-bin-common (Ubuntu package)
emacs24 (Ubuntu package)
emacs (Ubuntu package)
emacs-el (Ubuntu package)
emacs25 (Ubuntu package)
emacs25-bin-common (Ubuntu package)
emacs25-common (Ubuntu package)
emacs25-el (Ubuntu package)
emacs24-bin-common (Ubuntu package)
emacs24-el (Ubuntu package)
org-mode (Ubuntu package)
elpa-org (Ubuntu package)
emacs (Red Hat package)
emacs
emacs-devel
emacs-nox
emacs-common
emacs-lucid
emacs-debugsource
emacs-debuginfo
emacs-terminal
emacs-filesystem
emacs-help
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2023-28617
Migration Toolkit for Runtimes - update to 1.1.0
Migration Toolkit for Containers - update to 1.7.9
Red Hat OpenShift Container Platform - addressed in versions 4.11.42, 4.12.16
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.12.3
emacs24-common (Ubuntu package) - update to Ubuntu Pro
emacs-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-bin-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs24 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-el (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs25 (Ubuntu package) - update to Ubuntu Pro
emacs25-bin-common (Ubuntu package) - update to Ubuntu Pro
emacs25-common (Ubuntu package) - update to Ubuntu Pro
emacs25-el (Ubuntu package) - update to Ubuntu Pro
emacs24-bin-common (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs24-el (Ubuntu package) - update to Ubuntu Pro
org-mode (Ubuntu package) - update to Ubuntu Pro
elpa-org (Ubuntu package) - update to Ubuntu Pro
IBM Cloud Pak for Watson AIOps - update to 4.2.0
emacs (Red Hat package) - addressed in versions 26.1-5.el8_1.1, 26.1-5.el8_2.1, 26.1-5.el8_4.1, 26.1-7.el8_6.1, 26.1-7.el8_7.1, 26.1-10.el8_8.2, 27.2-6.el9_0.1, 27.2-6.el9_1.1
emacs - update to 27.1-11
emacs-devel - update to 27.1-11
emacs-nox - update to 27.1-11
emacs-common - update to 27.1-11
emacs-lucid - update to 27.1-11
emacs-debugsource - update to 27.1-11
emacs-debuginfo - update to 27.1-11
emacs-terminal - update to 27.1-11
emacs-filesystem - update to 27.1-11
emacs-help - update to 27.1-11
emacs - addressed in versions 27.2-6.0.1, 27.2-8.0.2
emacs-common - addressed in versions 27.2-6.0.1, 27.2-8.0.2
emacs-lucid - addressed in versions 27.2-6.0.1, 27.2-8.0.2
emacs-nox - addressed in versions 27.2-6.0.1, 27.2-8.0.2
emacs-filesystem - addressed in versions 27.2-6.0.1, 27.2-8.0.2
emacs-terminal - addressed in versions 27.2-6.0.1, 27.2-8.0.2
emacs - update to 28.2-3
External References
- https://list.orgmode.org/tencent_04CF842704737012CCBCD63CD654DD41CA0A@qq.com/T/#m6ef8e7d34b25fe17b4cbb655b161edce18c6655e
- https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=8f8ec2ccf3f5ef8f38d68ec84a7e4739c45db485
- https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=a8006ea580ed74f27f974d60b598143b04ad1741
Related Security Bulletins
- Remote code execution in Org Mode for Emacs
- Ubuntu update for emacs24
- Red Hat Enterprise Linux 8 update for emacs
- Red Hat Enterprise Linux 8.6 Extended Update Support update for emacs
- Red Hat Enterprise Linux 8 update for emacs
- Red Hat Enterprise Linux 8.4 Extended Update Support update for emacs
- Red Hat Enterprise Linux 9.0 Extended Update Support update for emacs
- Red Hat Enterprise Linux 9 update for emacs
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC)
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Red Hat Enterprise Linux 8 update for emacs
- Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions update for emacs
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.12
- Multiple vulnerabilities in Migration Toolkit for Runtimes
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- openEuler update for emacs
- Amazon Linux AMI update for emacs
- Ubuntu update for emacs
- Ubuntu update for org-mode
- Anolis OS update for emacs
- Anolis OS update for emacs