CVE-2022-45939
Summary
| CVE | CVE-2022-45939 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-28 06:15:00 UTC |
| Updated | 2023-11-07 03:54:00 UTC |
| Description | GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may use the "ctags *" command (suggested in the ctags documentation) in a situation where the current working directory has contents that depend on untrusted input. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160586 Oracle Enterprise Linux Security Update for emacs (ELSA-2023-2366)
- 160682 Oracle Enterprise Linux Security Update for emacs (ELSA-2023-3042)
- 181472 Debian Security Update for emacs (DSA 5314-1)
- 181496 Debian Security Update for emacs (DLA 3257-1)
- 183376 Debian Security Update for emacsxemacs21 (CVE-2022-45939)
- 241419 Red Hat Update for emacs (RHSA-2023:2366)
- 241509 Red Hat Update for emacs (RHSA-2023:3042)
- 243011 Red Hat Update for emacs (RHSA-2024:1103)
- 283576 Fedora Security Update for emacs (FEDORA-2022-d69c7f95a4)
- 283590 Fedora Security Update for emacs (FEDORA-2022-e37f239f2e)
- 284283 Fedora Security Update for emacs (FEDORA-2022-cbc71cc4fe)
- 354714 Amazon Linux Security Advisory for emacs : ALAS2022-2023-277
- 354732 Amazon Linux Security Advisory for emacs : ALAS2-2023-1928
- 354861 Amazon Linux Security Advisory for emacs : ALAS-2023-1712
- 355076 Amazon Linux Security Advisory for emacs : AL2012-2023-400
- 355171 Amazon Linux Security Advisory for emacs : ALAS2023-2023-108
- 355223 Amazon Linux Security Advisory for emacs : ALAS2023-2023-122
- 502847 Alpine Linux Security Update for emacs
- 503180 Alpine Linux Security Update for emacs
- 506040 Alpine Linux Security Update for emacs
- 672633 EulerOS Security Update for emacs (EulerOS-SA-2023-1354)
- 672643 EulerOS Security Update for emacs (EulerOS-SA-2023-1382)
- 672714 EulerOS Security Update for emacs (EulerOS-SA-2023-1465)
- 672763 EulerOS Security Update for emacs (EulerOS-SA-2023-1440)
- 672846 EulerOS Security Update for emacs (EulerOS-SA-2023-1582)
- 672852 EulerOS Security Update for emacs (EulerOS-SA-2023-1572)
- 672857 EulerOS Security Update for emacs (EulerOS-SA-2023-1593)
- 691026 Free Berkeley Software Distribution (FreeBSD) Security Update for emacs (76e2fcce-92d2-11ed-a635-080027f5fec9)
- 752965 SUSE Enterprise Linux Security Update for emacs (SUSE-SU-2022:4310-1)
- 752969 SUSE Enterprise Linux Security Update for emacs (SUSE-SU-2022:4305-1)
- 752980 SUSE Enterprise Linux Security Update for emacs (SUSE-SU-2022:4304-1)
- 904609 Common Base Linux Mariner (CBL-Mariner) Security Update for emacs (11515)
- 904783 Common Base Linux Mariner (CBL-Mariner) Security Update for emacs (11515-1)
- 941029 AlmaLinux Security Update for emacs (ALSA-2023:2366)
- 941074 AlmaLinux Security Update for emacs (ALSA-2023:3042)