OS Command Injection in emacs (Red Hat package) - CVE-2023-2491
Published: May 9, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to a missing fix for #VU74578 (CVE-2023-28617). A remote attacker can trick the victim to open a specially crafted file and execute arbitrary OS commands on the target system via a file name or directory name that contains shell metacharacters.
Affected software
emacs
emacs-common
emacs-lucid
emacs-nox
emacs-filesystem
emacs-terminal
Oracle Linux
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Node Health Check Operator
Multicluster Engine for Kubernetes
OpenShift Data Foundation (formerly OpenShift Container Storage)
OpenShift API for Data Protection (OADP)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Migration Toolkit for Runtimes
Red Hat OpenShift Dev Spaces
OpenShift Developer Tools and Services
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2023-2491
Node Health Check Operator - update to 0.4.1
OpenShift API for Data Protection (OADP) - update to 1.1.5
Migration Toolkit for Containers - update to 1.7.10
Multicluster Engine for Kubernetes - update to 2.2.4
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.73.5, 3.74.4
OpenShift Data Foundation (formerly OpenShift Container Storage) - addressed in versions 4.11.9, 4.12.4, 4.13.0
Red Hat OpenShift Container Platform - update to 4.13.2
OpenShift Logging - update to 5.7.2
Migration Toolkit for Runtimes - update to 1.1.1
Red Hat OpenShift Dev Spaces - update to 3.15.0
IBM Cloud Pak for Watson AIOps - update to 4.2.0
emacs - update to 27.2-8.0.2
emacs-common - update to 27.2-8.0.2
emacs-lucid - update to 27.2-8.0.2
emacs-nox - update to 27.2-8.0.2
emacs-filesystem - update to 27.2-8.0.2
emacs-terminal - update to 27.2-8.0.2
External References
Related Security Bulletins
- Red Hat Enterprise Linux 9 update for emacs
- Red Hat Enterprise Linux 8 update for emacs
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.2
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.73
- Multiple vulnerabilities in Red Hat Advanced Cluster Security for Kubernetes 3.74
- Multiple vulnerabilities in Red Hat OpenShift Logging 5.7
- OpenShift Data Foundation 4.12 update for kube-apiserver
- Migration Toolkit for Containers (MTC) 1.7 update for golang
- Multiple vulnerabilities in OpenShift Developer Tools and Services 4.11
- Multiple vulnerabilities in OpenShift Developer Tools and Services 4.12
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in Migration Toolkit for Runtimes
- Multiple vulnerabilities in OpenShift API for Data Protection (OADP)
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.11
- Multiple vulnerabilities in Red Hat OpenShift Container Platform release 4.13
- Multiple vulnerabilities in Node Health Check Operator 0.4
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Anolis OS update for emacs