{"id":"USN-7027-1","summary":"emacs, emacs24, emacs25 vulnerabilities","details":"It was discovered that Emacs incorrectly handled input sanitization. An\nattacker could possibly use this issue to execute arbitrary commands. This\nissue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04\nLTS. (CVE-2022-45939)\n\nXi Lu discovered that Emacs incorrectly handled input sanitization. An\nattacker could possibly use this issue to execute arbitrary commands. This\nissue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS\nand Ubuntu 22.04 LTS. (CVE-2022-48337)\n\nXi Lu discovered that Emacs incorrectly handled input sanitization. An\nattacker could possibly use this issue to execute arbitrary commands. This\nissue only affected Ubuntu 22.04 LTS. (CVE-2022-48338)\n\nXi Lu discovered that Emacs incorrectly handled input sanitization. An\nattacker could possibly use this issue to execute arbitrary commands. This\nissue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04\nLTS. (CVE-2022-48339)\n\nIt was discovered that Emacs incorrectly handled filename sanitization. An\nattacker could possibly use this issue to execute arbitrary commands. This\nissue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04\nLTS. (CVE-2023-28617)\n\nIt was discovered that Emacs incorrectly handled certain crafted files. An\nattacker could possibly use this issue to crash the program, resulting in\na denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu\n18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2024-30203,\nCVE-2024-30204, CVE-2024-30205)\n\nIt was discovered that Emacs incorrectly handled certain crafted files. An\nattacker could possibly use this issue to execute arbitrary commands.\n(CVE-2024-39331)\n","modified":"2026-02-10T04:45:27Z","published":"2024-09-19T17:16:05Z","related":["UBUNTU-CVE-2022-45939","UBUNTU-CVE-2022-48337","UBUNTU-CVE-2022-48338","UBUNTU-CVE-2022-48339","UBUNTU-CVE-2023-28617","UBUNTU-CVE-2024-30203","UBUNTU-CVE-2024-30204","UBUNTU-CVE-2024-30205","UBUNTU-CVE-2024-39331"],"upstream":["CVE-2022-45939","CVE-2022-48337","CVE-2022-48338","CVE-2022-48339","CVE-2023-28617","CVE-2024-30203","CVE-2024-30204","CVE-2024-30205","CVE-2024-39331","UBUNTU-CVE-2022-45939","UBUNTU-CVE-2022-48337","UBUNTU-CVE-2022-48338","UBUNTU-CVE-2022-48339","UBUNTU-CVE-2023-28617","UBUNTU-CVE-2024-30203","UBUNTU-CVE-2024-30204","UBUNTU-CVE-2024-30205","UBUNTU-CVE-2024-39331"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7027-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-45939"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-48337"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-48338"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-48339"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-28617"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-30203"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-30204"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-30205"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-39331"},{"type":"REPORT","url":"https://launchpad.net/bugs/2070418"}],"affected":[{"package":{"name":"emacs24","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/emacs24@24.5+1-6ubuntu1.1+esm4?arch=source&distro=esm-infra/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.5+1-6ubuntu1.1+esm4"}]}],"versions":["24.5+1-1ubuntu2","24.5+1-1ubuntu4","24.5+1-1ubuntu5","24.5+1-1ubuntu6","24.5+1-1ubuntu7","24.5+1-6ubuntu1","24.5+1-6ubuntu1.1","24.5+1-6ubuntu1.1+esm1","24.5+1-6ubuntu1.1+esm2","24.5+1-6ubuntu1.1+esm3"],"ecosystem_specific":{"binaries":[{"binary_name":"emacs24","binary_version":"24.5+1-6ubuntu1.1+esm4"},{"binary_name":"emacs24-bin-common","binary_version":"24.5+1-6ubuntu1.1+esm4"},{"binary_name":"emacs24-common","binary_version":"24.5+1-6ubuntu1.1+esm4"},{"binary_name":"emacs24-el","binary_version":"24.5+1-6ubuntu1.1+esm4"},{"binary_name":"emacs24-lucid","binary_version":"24.5+1-6ubuntu1.1+esm4"},{"binary_name":"emacs24-nox","binary_version":"24.5+1-6ubuntu1.1+esm4"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2022-48337","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-30203","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-30204","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-30205","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-39331","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:Pro:16.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7027-1.json"}},{"package":{"name":"emacs25","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/emacs25@25.2+1-6ubuntu0.1~esm2?arch=source&distro=esm-infra/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.2+1-6ubuntu0.1~esm2"}]}],"versions":["25.2+1-6"],"ecosystem_specific":{"binaries":[{"binary_name":"emacs25","binary_version":"25.2+1-6ubuntu0.1~esm2"},{"binary_name":"emacs25-bin-common","binary_version":"25.2+1-6ubuntu0.1~esm2"},{"binary_name":"emacs25-common","binary_version":"25.2+1-6ubuntu0.1~esm2"},{"binary_name":"emacs25-el","binary_version":"25.2+1-6ubuntu0.1~esm2"},{"binary_name":"emacs25-lucid","binary_version":"25.2+1-6ubuntu0.1~esm2"},{"binary_name":"emacs25-nox","binary_version":"25.2+1-6ubuntu0.1~esm2"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2022-45939","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-48337","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-48339","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2023-28617","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-30203","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-30204","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-30205","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-39331","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:Pro:18.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7027-1.json"}},{"package":{"name":"emacs","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/emacs@1:26.3+1-1ubuntu2+esm1?arch=source&distro=esm-apps/focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:26.3+1-1ubuntu2+esm1"}]}],"versions":["1:26.3+1-1ubuntu1","1:26.3+1-1ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"emacs","binary_version":"1:26.3+1-1ubuntu2+esm1"},{"binary_name":"emacs-bin-common","binary_version":"1:26.3+1-1ubuntu2+esm1"},{"binary_name":"emacs-common","binary_version":"1:26.3+1-1ubuntu2+esm1"},{"binary_name":"emacs-el","binary_version":"1:26.3+1-1ubuntu2+esm1"},{"binary_name":"emacs-gtk","binary_version":"1:26.3+1-1ubuntu2+esm1"},{"binary_name":"emacs-lucid","binary_version":"1:26.3+1-1ubuntu2+esm1"},{"binary_name":"emacs-nox","binary_version":"1:26.3+1-1ubuntu2+esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2022-45939","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-48337","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-48339","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2023-28617","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-30203","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-30204","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-30205","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-39331","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:Pro:20.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7027-1.json"}},{"package":{"name":"emacs","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/emacs@1:27.1+1-3ubuntu5.2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:27.1+1-3ubuntu5.2"}]}],"versions":["1:27.1+1-3ubuntu3","1:27.1+1-3ubuntu5","1:27.1+1-3ubuntu5.1"],"ecosystem_specific":{"binaries":[{"binary_name":"emacs","binary_version":"1:27.1+1-3ubuntu5.2"},{"binary_name":"emacs-bin-common","binary_version":"1:27.1+1-3ubuntu5.2"},{"binary_name":"emacs-common","binary_version":"1:27.1+1-3ubuntu5.2"},{"binary_name":"emacs-el","binary_version":"1:27.1+1-3ubuntu5.2"},{"binary_name":"emacs-gtk","binary_version":"1:27.1+1-3ubuntu5.2"},{"binary_name":"emacs-lucid","binary_version":"1:27.1+1-3ubuntu5.2"},{"binary_name":"emacs-nox","binary_version":"1:27.1+1-3ubuntu5.2"}],"availability":"No subscription required"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2022-45939","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-48337","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-48338","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-48339","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2023-28617","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-30203","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-30204","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-30205","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2024-39331","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:22.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7027-1.json"}},{"package":{"name":"emacs","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/emacs@1:29.3+1-1ubuntu2+esm1?arch=source&distro=esm-apps/noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:29.3+1-1ubuntu2+esm1"}]}],"versions":["1:29.1+1-5ubuntu1","1:29.2+1-1ubuntu1","1:29.2+1-2ubuntu4","1:29.3+1-1ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"emacs","binary_version":"1:29.3+1-1ubuntu2+esm1"},{"binary_name":"emacs-bin-common","binary_version":"1:29.3+1-1ubuntu2+esm1"},{"binary_name":"emacs-common","binary_version":"1:29.3+1-1ubuntu2+esm1"},{"binary_name":"emacs-el","binary_version":"1:29.3+1-1ubuntu2+esm1"},{"binary_name":"emacs-gtk","binary_version":"1:29.3+1-1ubuntu2+esm1"},{"binary_name":"emacs-lucid","binary_version":"1:29.3+1-1ubuntu2+esm1"},{"binary_name":"emacs-nox","binary_version":"1:29.3+1-1ubuntu2+esm1"},{"binary_name":"emacs-pgtk","binary_version":"1:29.3+1-1ubuntu2+esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2024-39331","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:Pro:24.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7027-1.json"}}],"schema_version":"1.7.3"}