First published: Thu Mar 27 2025(Updated: )
It was discovered that Org Mode did not correctly handle filenames containing shell metacharacters. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-28617) It was discovered that Org Mode could run untrusted code left in its buffer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-30202) It was discovered that Org Mode did not correctly handle the contents of remote files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-30205) It was discovered that Org Mode could be made to run arbitrary Elisp code. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-39331)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/elpa-org | <9.6.10+dfsg-1ubuntu0.1~esm1 | 9.6.10+dfsg-1ubuntu0.1~esm1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/elpa-org | <9.5.2+dfsh-4ubuntu0.1~esm1 | 9.5.2+dfsh-4ubuntu0.1~esm1 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/elpa-org | <9.3.1+dfsg-1ubuntu0.1~esm1 | 9.3.1+dfsg-1ubuntu0.1~esm1 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/elpa-org | <9.1.6+dfsg-1ubuntu0.1~esm1 | 9.1.6+dfsg-1ubuntu0.1~esm1 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/org-mode | <8.3.3-2ubuntu0.1~esm1 | 8.3.3-2ubuntu0.1~esm1 |
Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-7375-1 is critical due to the potential for denial of service and arbitrary code execution.
To fix USN-7375-1, update the elpa-org or org-mode packages to the latest recommended versions for your Ubuntu release.
USN-7375-1 affects Ubuntu versions 16.04, 18.04, 20.04, 22.04, and 24.04.
USN-7375-1 involves the elpa-org and org-mode packages in Ubuntu.
USN-7375-1 addresses vulnerabilities related to improper handling of filenames containing shell metacharacters.