Insufficient verification of data authenticity in Emacs - CVE-2024-30204

 

Insufficient verification of data authenticity in Emacs - CVE-2024-30204

Published: March 26, 2024


Vulnerability identifier: #VU87809
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-30204
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to LaTeX preview is enabled by default for e-mail attachments. A remote attacker can trick the victim to open a specially crafted file and execute arbitrary code on the system.

Affected software

Emacs
Oracle Solaris
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Desktop 15
SUSE Enterprise Storage
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
Desktop Applications Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Voice Gateway
emacs24-el (Ubuntu package)
emacs24-common (Ubuntu package)
emacs24-bin-common (Ubuntu package)
emacs24 (Ubuntu package)
emacs25-el (Ubuntu package)
emacs25-common (Ubuntu package)
emacs25-bin-common (Ubuntu package)
emacs25 (Ubuntu package)
emacs-el (Ubuntu package)
emacs-common (Ubuntu package)
emacs-bin-common (Ubuntu package)
emacs (Ubuntu package)
app-editors/emacs
emacs-info
emacs-el
emacs
etags-debuginfo
etags
emacs-debugsource
emacs-debuginfo
emacs-nox-debuginfo
emacs-x11
emacs-nox
emacs-x11-debuginfo
emacs-devel
emacs-common
emacs-filesystem
emacs-terminal
emacs-help
emacs-lucid
emacs (Red Hat package)
emacs-doc

How to mitigate CVE-2024-30204

Install updates from vendor's website.

Emacs - update to 29.3
Oracle Solaris - update to 11.4 SRU 71
Voice Gateway - update to 1.0.8.12
emacs24-el (Ubuntu package) - update to Ubuntu Pro
emacs24-common (Ubuntu package) - update to Ubuntu Pro
emacs24-bin-common (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs24 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
emacs25-el (Ubuntu package) - update to Ubuntu Pro
emacs25-common (Ubuntu package) - update to Ubuntu Pro
emacs25-bin-common (Ubuntu package) - update to Ubuntu Pro
emacs25 (Ubuntu package) - update to Ubuntu Pro
emacs-el (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs-bin-common (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
emacs (Ubuntu package) - addressed in versions Ubuntu Pro, 1:27.1+1-3ubuntu5.2
app-editors/emacs - update to 9.6.23
emacs-info - addressed in versions 24.3-25.17.1, 25.3-150000.3.22.1, 27.2-150400.3.11.1
emacs-el - addressed in versions 24.3-25.17.1, 25.3-150000.3.22.1, 27.2-150400.3.11.1
emacs - addressed in versions 24.3-25.17.1, 25.3-150000.3.22.1, 27.2-150400.3.11.1
etags-debuginfo - addressed in versions 24.3-25.17.1, 25.3-150000.3.22.1, 27.2-150400.3.11.1
etags - addressed in versions 24.3-25.17.1, 25.3-150000.3.22.1, 27.2-150400.3.11.1
emacs-debugsource - addressed in versions 24.3-25.17.1, 25.3-150000.3.22.1, 27.2-150400.3.11.1
emacs-debuginfo - addressed in versions 24.3-25.17.1, 25.3-150000.3.22.1, 27.2-150400.3.11.1
emacs-nox-debuginfo - addressed in versions 24.3-25.17.1, 25.3-150000.3.22.1, 27.2-150400.3.11.1
emacs-x11 - addressed in versions 24.3-25.17.1, 25.3-150000.3.22.1, 27.2-150400.3.11.1
emacs-nox - addressed in versions 24.3-25.17.1, 25.3-150000.3.22.1, 27.2-150400.3.11.1
emacs-x11-debuginfo - addressed in versions 24.3-25.17.1, 25.3-150000.3.22.1, 27.2-150400.3.11.1
emacs-devel - update to 27.1-13
emacs-common - update to 27.1-13
emacs-debugsource - update to 27.1-13
emacs-nox - update to 27.1-13
emacs-filesystem - update to 27.1-13
emacs-terminal - update to 27.1-13
emacs-help - update to 27.1-13
emacs-debuginfo - update to 27.1-13
emacs-lucid - update to 27.1-13
emacs - update to 27.1-13
emacs (Red Hat package) - update to 27.2-10.el9
emacs - addressed in versions 27.2-10.0.1, 29.4-1
emacs-common - addressed in versions 27.2-10.0.1, 29.4-1
emacs-lucid - addressed in versions 27.2-10.0.1, 29.4-1
emacs-nox - addressed in versions 27.2-10.0.1, 29.4-1
emacs-doc - addressed in versions 27.2-10.0.1, 29.4-1
emacs-filesystem - addressed in versions 27.2-10.0.1, 29.4-1
emacs-terminal - addressed in versions 27.2-10.0.1, 29.4-1
emacs - addressed in versions 29.3-1.fc38, 29.3-1.fc39, 29.3-1.fc40
emacs-devel - update to 29.4-1

External References

Related Security Bulletins