NA

CVE-2023-27985

Published: 09/03/2023 Updated: 09/06/2023
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

emacsclient-mail.desktop in Emacs 28.1 up to and including 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu emacs

Vendor Advisories

Debian Bug report logs - #1032538 emacs: CVE-2023-27985 CVE-2023-27986 Package: src:emacs; Maintainer for src:emacs is Rob Browning <rlb@defaultvalueorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 8 Mar 2023 20:00:04 UTC Severity: grave Tags: security, upstream Found in version emacs/1:282+ ...
DescriptionThe MITRE CVE dictionary describes this issue as: emacsclient-maildesktop in Emacs 281 through 282 is vulnerable to shell command injections through a crafted mailto: URI This is related to lack of compliance with the Desktop Entry Specification ...