Article 78CKS Emacs arbitrary code execution flaw

Emacs arbitrary code execution flaw

by
jzb
from LWN.net on (#78CKS)

Sean Whitton has announcedthat the original fix for an arbitrary code execution flaw in Emacs (CVE-2024-53920) wasincomplete. Bas Alberts discovered that viewing or editing untrusted files inmodes other than Emacs's Lisp mode can also result in arbitrary codeexecution.

This problem affects all Emacs versions affected by CVE-2024-53920.This means Emacs 24 and newer, and possibly also older versions.

A minimal fix, attached, is queued up for release with Emacs 31.2.We (the Emacs upstream maintainers) don't expect to backport the fix toolder Emacs releases ourselves.

LWN covered the originalvulnerability in December 2024.

External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments