Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Lux

#32923de 53,633
7.8CVSS total
Vulnerabilidades · 1
PT-2023-21850
7.8
2023-03-18
Gnu Emacs · Gnu Emacs · CVE-2023-28617
**Name of the Vulnerable Software and Affected Versions** Org Mode versions through 9.6.1 **Description** The issue allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters. This is possible due to a flaw in the `org-babel-execute:latex` function in `ob-latex.el` for GNU Emacs. **Recommendations** For versions through 9.6.1, consider disabling the `org-babel-execute:latex` function until a patch is available to prevent the execution of arbitrary commands. Restrict access to file names and directory names that may contain shell metacharacters to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.