In GNU Emacs 29.4, a vulnerability that could lead to code execution when opening a specially crafted file has been fixed.

The GNU Project has released the text editor GNU Emacs 29.4. The project's code is written in C and Lisp and is distributed under the GPLv3 license. GNU Emacs 29.4 is presented as an unplanned emergency release addressing a vulnerability (no CVE assigned). Details about the vulnerability have not yet been disclosed, only stating that arbitrary shell commands execution is prohibited when Org mode is enabled. Apparently, the vulnerability allows code execution when opening specific content in Emacs or when viewing specially formatted messages in the Emacs-integrated email/RSS/NNTP client Gnus.

Supplement: An example org file has been published, the opening of which in Emacs triggers shell command execution. The vulnerability can also be exploited by attaching such a file to an email, and it will execute upon previewing in Emacs.

#+LINK: shell %(shell-command-to-string)
[[shell:touch ~/hacked.txt]]

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster