A command injection flaw was found which could allow a remote, unauthenticated attacker to execute arbitrary shell commands by tricking users into visiting a specially crafted website or an HTTP URL with a redirect. . MGASA-2025-0075 - Updated emacs packages fix a security vulnerability Publication date: 25 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0075.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-1244 A command injection flaw was found which could allow a remote, unauthenticated attacker to execute arbitrary shell commands by tricking users into visiting a specially crafted website or an HTTP URL with a redirect. References: - https://bugs.mageia.org/show_bug.cgi?id=34045 - https://lwn.net/Articles/1011611/ - https://nvd.nist.gov/vuln/detail/CVE-2025-1244 - - https://www.cve.org/CVERecord?id=CVE-2025-1244 SRPMS: - 9/core/emacs-29.4-1.3.mga9 . Recent updates to Emacs packages for Mageia address a significant command injection vulnerability, which could enable remote execution by malicious attackers.. Mageia security, command injection, remote access, Emacs security. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.