CVE-2023-28617: OS Command Injection
Published Mar 19, 2023
·Updated
Last updated 27 March 2025
Other sources
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters.
Affected Software
3 affected componentsFixes available
GNU Org Mode Gnu Emacs<=9.6.1
debian/emacs<=1:27.1+1-3.1+deb11u5
1:27.1+1-3.1+deb11u61:28.2+1-15+deb12u41:30.1+1-5
debian/org-mode
9.4.0+dfsg-1+deb11u39.5.2+dfsh-59.7.27+dfsg-1
Remediation
Event History
Mar 19, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Mar 21, 2023
Data Sourced
via Red Hat·05:48 PM
DescriptionSeverityAffected Software
Sep 23, 2024
Data Sourced
via Launchpad·08:43 PM
Description
Mar 31, 2025
Data Sourced
via Ubuntu·02:40 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-28617.
2
What is the severity of CVE-2023-28617?
The severity of CVE-2023-28617 is high with a CVSS score of 7.8.
3
Which software is affected by CVE-2023-28617?
Org Mode through version 9.6.1 for GNU Emacs is affected by CVE-2023-28617.
4
How can attackers exploit CVE-2023-28617?
Attackers can exploit CVE-2023-28617 by executing arbitrary commands through a file or directory name that contains shell metacharacters.
5
Is there a fix available for CVE-2023-28617?
Yes, there are fixes available for CVE-2023-28617. Please refer to the provided references for more information.