Multiple vulnerabilities were discovered in GNU Emacs, the extensible, customisable, self-documenting, real-time display editor. CVE-2023-28617 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4069-1
Moderate: less security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:1610", "synopsis": "Moderate: less security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for less.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The \"less\" utility is a text file browser that resembles \"more\", but allows users to move backwards in the file as well as forwards. Since \"less\" does not read the entire input file at startup, it also starts more quickly than ordinary text editors.\n\nSecurity Fix(es):\n\n* less: missing quoting of shell metacharacters in LESSCLOSE handling (CVE-2022-48624)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2265081", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2265081", "description": ""}], "cves": [{"name": "CVE-2022-48624", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-48624", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-04-05T14:55:53.600745Z", "rpms": {"Rocky Linux 8": {"nvras": ["less-0:530-2.el8_9.aarch64.rpm", "less-0:530-2.el8_9.src.rpm", "less-0:530-2.el8_9.x86_64.rpm", "less-debuginfo-0:530-2.el8_9.aarch64.rpm", "less-debuginfo-0:530-2.el8_9.x86_64.rpm", "less-debugsource-0:530-2.el8_9.aarch64.rpm", "less-debugsource-0:530-2.el8_9.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. The update RLSA-2024:1610 for Rocky Linux brings significant security enhancements related to the 'less' command-line tool. Explore the details.. Rocky Linux RLSA, Less Utility Update, Moderate Security Fix. .LinuxSecurity.com Team
New emacs packages are available for Slackware 15.0 and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] emacs (SSA:2022-342-01) New emacs packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/emacs-27.2-i586-2_slack15.0.txz: Rebuilt. GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may use the "ctags *" command (suggested in the ctags documentation) in a situation where the current working directory has contents that depend on untrusted input. For more information, see: https://www.cve.org/CVERecord?id=CVE-2022-45939 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: 97de51db765e152d32a8cf5562961f81 emacs-27.2-i586-2_slack15.0.txz Slackware x86_64 15.0 package: 91209777290bf8fd5e2ac918d72f14ba emacs-27.2-x86_64-2_slack15.0.txz Slackware -current package: 8d0bb1c76fe4e50fa33ecc6c3aaffce1 e/emacs-28.2-i586-2.txz Slackware x86_64 -current package: 3f8c307bb6e7e867cd360c4fa914a70f e/emacs-28.2-x86_64-2.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg emacs-27.2-i586-2_slack15.0.txz +-----+ . Recent Emacs updates forSlackware address an urgent security flaw in versions 15.0 and -current. Please upgrade without delay!. Emacs Security, Slackware Update, Package Upgrade, Command Execution, Shell Metacharacters. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.