drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Mehrere Probleme in Org Mode
| Name: |
Mehrere Probleme in Org Mode |
|
| ID: |
USN-7375-1 |
|
| Distribution: |
Ubuntu |
|
| Plattformen: |
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS |
|
| Datum: |
Do, 27. März 2025, 07:19 |
|
| Referenzen: |
https://www.cve.org/CVERecord?id=CVE-2024-39331
https://www.cve.org/CVERecord?id=CVE-2023-28617
https://www.cve.org/CVERecord?id=CVE-2024-30202
https://www.cve.org/CVERecord?id=CVE-2024-30205 |
|
| Applikationen: |
Emacs |
|
Originalnachricht |
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --===============3158589344408477734== Content-Language: en-US Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="------------v8cfWHc2oX1LQx6c1ecpMR3r"
This is an OpenPGP/MIME signed message (RFC 4880 and 3156) --------------v8cfWHc2oX1LQx6c1ecpMR3r Content-Type: multipart/mixed; boundary="------------HXd5oalm9Amc9zPYC0zxP0XX"; protected-headers="v1" From: Bruce Cable <bruce.cable@canonical.com> Reply-To: Ubuntu Security <security@ubuntu.com> To: ubuntu-security-announce@lists.ubuntu.com Message-ID: <0247e88e-bfb2-49fb-a312-6874a8d0b5ee@canonical.com> Subject: [USN-7375-1] Org Mode vulnerabilities
--------------HXd5oalm9Amc9zPYC0zxP0XX Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: base64
========================================================================== Ubuntu Security Notice USN-7375-1 March 27, 2025
org-mode vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in Org Mode.
Software Description: - org-mode: keep notes, maintain ToDo lists, and do project planning in emacs
Details:
It was discovered that Org Mode did not correctly handle filenames containing shell metacharacters. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-28617)
It was discovered that Org Mode could run untrusted code left in its buffer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-30202)
It was discovered that Org Mode did not correctly handle the contents of remote files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2024-30205)
It was discovered that Org Mode could be made to run arbitrary Elisp code. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-39331)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04 LTS elpa-org 9.6.10+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro
Ubuntu 22.04 LTS elpa-org 9.5.2+dfsh-4ubuntu0.1~esm1 Available with Ubuntu Pro
Ubuntu 20.04 LTS elpa-org 9.3.1+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro
Ubuntu 18.04 LTS elpa-org 9.1.6+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro
Ubuntu 16.04 LTS org-mode 8.3.3-2ubuntu0.1~esm1 Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References: https://ubuntu.com/security/notices/USN-7375-1 CVE-2023-28617, CVE-2024-30202, CVE-2024-30205, CVE-2024-39331
--------------HXd5oalm9Amc9zPYC0zxP0XX--
--------------v8cfWHc2oX1LQx6c1ecpMR3r Content-Type: application/pgp-signature; name="OpenPGP_signature.asc" Content-Description: OpenPGP digital signature Content-Disposition: attachment; filename="OpenPGP_signature.asc"
-----BEGIN PGP SIGNATURE-----
wsD5BAABCAAjFiEEkd98mdFcnQdP7vQkuGrtzot7pOcFAmfktbAFAwAAAAAACgkQuGrtzot7pOcJ zwv/bo5gh2dEIPkLfZhZe6THgYmbd8ZJXyqAYpTyJdjfG61XaEjH2ZSglKzJZK5RL1pNz53KVeze eWPYnsrZ4BLAFQ7bqDtvfznqTUUGSKWrmTJ9p8PMT4p0cVwjsZ1qHOXXMnBD/uuf2Q0lHCP10eBm 3i4JvEKrs1AAOsTKwMBWkRkP+VSq1TJYwwJQy5E/p4pR2zONA2A55n3BUf+X5joe76Rg11mcxAaO Kzqi/Sak2GytTdtAnTg30Km1PUsF5stGUFECARw1GsM0Roa7uRDhFcLE8oHjd4kysZHx57+q46c6 O3DlYqzHfRSMjVbyyLmThg+qqITVLj6v7Ia0llzydYa2K4qHjm+MVu95bIgxSxEUSDJJrggFRiVP a25iIp1yZFG0B3oZrDYoZnyLb1tW+MM3lSfidT3XpGtRGLRzVpHIYyl7nnXZWx1/LkozWtHTbn31 H+vnv7I3Mvq+rvGLpdLHsDOgyFCiygDSFuLRhrgSVqZSOXpDj03OQijQd1jc =IBZv -----END PGP SIGNATURE-----
--------------v8cfWHc2oX1LQx6c1ecpMR3r--
--===============3158589344408477734== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
Cg==
--===============3158589344408477734==--
|
|
|
|