https://seclists.org/oss-sec/2024/q2/299: Arbitrary shell command evaluation in Org mode (GNU Emacs)
Published Jun 24, 2024
·Updated
Affected Software
2 affected components
GNU Emacs
GNU Org mode
Frequently Asked Questions
1
What is the severity of CVE-2024-XXXX?
The severity of CVE-2024-XXXX has been rated as high due to the potential for arbitrary shell command evaluation.
2
How do I fix CVE-2024-XXXX?
To fix CVE-2024-XXXX, customize mm-automatic-display to remove text/x-org from the list of MIME types for automatic previewing.
3
What software is affected by CVE-2024-XXXX?
CVE-2024-XXXX affects GNU Emacs and GNU Org mode.
4
When was CVE-2024-XXXX published?
CVE-2024-XXXX was published on June 24, 2024.
5
What functionality does CVE-2024-XXXX compromise?
CVE-2024-XXXX compromises the security of automatic previewing of org-mode attachments, allowing arbitrary command execution.