Security
Emacs arbitrary code execution flaw
jzb LWN.net
4 views
Sean Whitton has announced
that the original fix for an arbitrary code execution flaw in Emacs (CVE-2024-53920) was
incomplete. Bas Alberts discovered that viewing or editing untrusted files in
modes other than Emacs's Lisp mode can also result in arbitrary code
execution.
This problem affects all Emacs versions affected by CVE-2024-53920.
This means Emacs 24 and newer, and possibly also older versions.
A minimal fix, attached, is queued up for release with Emacs 31.2.
We (the Emacs upstream maintainers) don't expect to backport the fix to
older Emacs releases ourselves.
LWN covered the original
vulnerability in December 2024.
Read original: https://lwn.net/Articles/1094224/
← Previous
Fixing Angular NG02100 & [object Object] Issues by Sanitizing API Responses
Next →
How to Price Web Design Projects: A Practical Guide for Freelancers
Related
Designing a Privacy-First Architecture for Sensitive Data: Zero-IP Logging, Postgres RLS, and AI Safety
Security
0
Dev.to (EN Zone)
Patch Rollback Risk: When Recovery Reintroduces the Exposure You Just Closed
Security
0
DEV Community
I built a chat app that forgets 🔥
Security
3
Dev.to (EN Zone)
Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development
Security
2
SecurityWeek
Comments0
No comments yet — be the first