OS Command Injection in emacs (Red Hat package) - CVE-2023-2491

 

OS Command Injection in emacs (Red Hat package) - CVE-2023-2491

Published: May 9, 2023


Vulnerability identifier: #VU75915
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2491
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to a missing fix for #VU74578 (CVE-2023-28617). A remote attacker can trick the victim to open a specially crafted file and execute arbitrary OS commands on the target system via a file name or directory name that contains shell metacharacters.


Affected software

emacs (Red Hat package)
emacs
emacs-common
emacs-lucid
emacs-nox
emacs-filesystem
emacs-terminal
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Node Health Check Operator
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Migration Toolkit for Runtimes
Red Hat OpenShift Dev Spaces
OpenShift Developer Tools and Services
IBM Cloud Pak for Watson AIOps

How to mitigate CVE-2023-2491

Install updates from vendor's website.

emacs (Red Hat package) - addressed in versions 27.2-8.el9_2.1, 26.1-10.el8_8.2
Node Health Check Operator - update to 0.4.1
OpenShift API for Data Protection (OADP) - update to 1.1.5
Migration Toolkit for Containers - update to 1.7.10
Multicluster Engine for Kubernetes - update to 2.2.4
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.73.5, 3.74.4
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.11.9, 4.12.4, 4.13.0
Red Hat OpenShift Container Platform - update to 4.13.2
OpenShift Logging - update to 5.7.2
Migration Toolkit for Runtimes - update to 1.1.1
Red Hat OpenShift Dev Spaces - update to 3.15.0
IBM Cloud Pak for Watson AIOps - update to 4.2.0
emacs - update to 27.2-8.0.2
emacs-common - update to 27.2-8.0.2
emacs-lucid - update to 27.2-8.0.2
emacs-nox - update to 27.2-8.0.2
emacs-filesystem - update to 27.2-8.0.2
emacs-terminal - update to 27.2-8.0.2

External References

Related Security Bulletins