QID 355076

Date Published: 2023-05-18

QID 355076: Amazon Linux Security Advisory for emacs : AL2012-2023-400

Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-48339:
A flaw was found in the Emacs package. If a file name or directory name contains shell metacharacters, arbitrary code may be executed. 2171989: CVE-2022-48339 emacs: command injection vulnerability in htmlfontify.el CVE-2022-48337:
A flaw was found in the Emacs package. This flaw allows attackers to execute commands via shell metacharacters in the name of a source-code file. 2171987: CVE-2022-48337 emacs: command execution via shell metacharacters CVE-2022-45939:
A flaw was found in Etags, the Ctags implementation of Emacs. A file with a crafted filename may result in arbitrary command execution when processed by Etags. 2149380: CVE-2022-45939 emacs: ctags local command execution vulnerability

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Administrators are advised to apply the appropriate software updates.
    Vendor References

    CVEs related to QID 355076

    Software Advisories
    Advisory ID Software Component Link
    AL2012-2023-400 Amazon Linux Bare Metal URL Logo docs.aws.amazon.com/AWSEC2/latest/UserGuide/install-updates.html