CVE-2024-30205
Published: 25 March 2024
In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
Priority
Status
Package | Release | Status |
---|---|---|
emacs Launchpad, Ubuntu, Debian |
focal |
Needs triage
|
jammy |
Needs triage
|
|
mantic |
Needs triage
|
|
upstream |
Needs triage
|
|
emacs24 Launchpad, Ubuntu, Debian |
focal |
Does not exist
|
jammy |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Needs triage
|
|
emacs25 Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Needs triage
|
|
org-mode Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Needs triage
|
|
jammy |
Needs triage
|
|
mantic |
Needs triage
|
|
upstream |
Needs triage
|
|
xenial |
Needs triage
|
|
xemacs21 Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Needs triage
|
|
jammy |
Needs triage
|
|
mantic |
Needs triage
|
|
upstream |
Ignored
(end of life)
|
|
xenial |
Needs triage
|
|
xemacs21-packages Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Needs triage
|
|
jammy |
Needs triage
|
|
mantic |
Needs triage
|
|
upstream |
Needs triage
|
|
xenial |
Needs triage
|
References
- https://www.openwall.com/lists/oss-security/2024/03/24/1
- https://lists.gnu.org/archive/html/info-gnu/2024-03/msg00005.html
- https://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=2bc865ace050ff118db43f01457f95f95112b877
- https://list.orgmode.org/87o7b3eczr.fsf@bzg.fr/T/#t
- https://git.savannah.gnu.org/cgit/emacs/org-mode.git/commit/?id=4255d5dcc0657915f90e4fba7e0a5514cced514d
- https://git.savannah.gnu.org/cgit/emacs.git/tree/etc/NEWS?h=emacs-29
- https://www.cve.org/CVERecord?id=CVE-2024-30205
- NVD
- Launchpad
- Debian