CVE Database
/

CVE-2017-14482

Back to search

CVE-2017-14482

Published: Sep 14, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).

VendorProductVersions

n/a

n/a

affected
n/a

References

DSA-3975
vendor-advisory
x_refsource_DEBIAN
DSA-3970
vendor-advisory
x_refsource_DEBIAN
GLSA-201801-07
vendor-advisory
x_refsource_GENTOO
RHSA-2017:2771
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now