emacs-24.3-23.1.0.2.el7.AXS7

エラータID: AXSA:2024-8928:04

Release date: 
Tuesday, October 22, 2024 - 09:44
Subject: 
emacs-24.3-23.1.0.2.el7.AXS7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

contains special code editing features, a scripting language (elisp), and the
capability to read mail, news, and more without leaving the editor.

This package provides an emacs binary with support for X windows.

Security Fix(es):

* CVE-2022-45939: fix ctags local command injection vulnerability

CVE(s):
CVE-2022-45939
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may use the "ctags *" command (suggested in the ctags documentation) in a situation where the current working directory has contents that depend on untrusted input.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

Asianux Server 7 for x86_64
  1. emacs-24.3-23.1.0.2.el7.AXS7.x86_64.rpm
    MD5: b9874dcb14089de9f66e1425bd84e637
    SHA-256: 9d3fef742e4451aaaa662cc2701c388e404bdb8324a371e131c6ce379e75c348
    Size: 2.87 MB
  2. emacs-common-24.3-23.1.0.2.el7.AXS7.x86_64.rpm
    MD5: eb14998eb8b3b8a9c535b852b28fabc7
    SHA-256: 8a8d4eefc3a126ae0ebb6441adb6fe9458057713fd55718d6419f6ed22d7c7ea
    Size: 20.47 MB
  3. emacs-filesystem-24.3-23.1.0.2.el7.AXS7.noarch.rpm
    MD5: 782114d321657c2353b4970d686e53e4
    SHA-256: 0760fa9d931a5fd339c970cecf2cf2794d0cb644bb8108effc3dc3b104ebc829
    Size: 57.91 kB
  4. emacs-nox-24.3-23.1.0.2.el7.AXS7.x86_64.rpm
    MD5: eaab79fb6ea6bc8108c915a5cbbac73a
    SHA-256: 673020e58b8b967ca4b0648e0eb25c057c5c9679e327587942ca5fddfcb9965a
    Size: 2.43 MB