Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 17.04 USN-3428-1 Critical: Emacs Code Execution Threat

ubuntu
Calendar Grey September 21, 2017
Scroller Ubuntu
New information regarding the emacs25 security flaw in Ubuntu could lead to potential code execution risks; please examine the advisory released on September 21, 2017.
Emacs could be made to run programs as your login if it opened a specially crafted file.

Summary

Emacs could be made to run programs as your login if it opened a

specially crafted file.

Software Description:

- emacs25: GNU Emacs editor

Details:

Charles A. Roelli discovered that Emacs incorrectly handled certain

files. If a user were tricked into opening a specially crafted file, an

attacker could possibly use this to execute arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 17.04:
  emacs25                         25.1+1-3ubuntu4.1

In general, a standard system update will make all the necessary
changes.

References

  https://ubuntu.com/security/notices/USN-3428-1

  CVE-2017-14482

Severity
critical
Lowest
Low
Medium
High
Critical

September 21, 2017

Package Information

  https://launchpad.net/ubuntu/+source/emacs25/25.1+1-3ubuntu4.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.