Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1148702

Bug#1033341: org-mode: CVE-2023-28617

From Nicholas D Steeves <sten@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.maint.emacsen
Subject Bug#1033341: org-mode: CVE-2023-28617
Date 2023-06-04 04:10 +0200
Message-ID <GCLlT-duIa-1@gated-at.bofh.it> (permalink)
References <Gcevg-env1-3@gated-at.bofh.it> <Gcevg-env1-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

fixed 1033341 org/mode/9.5.2+dfsh-5
fixed 1033341 org-mode/9.6.6+dfsg-1~exp1
thanks

Dear Salvatore and Security Team,

Salvatore Bonaccorso <carnil@debian.org> writes:

> Source: org-mode
> Version: 9.5.2+dfsh-4
> Severity: important
> Tags: security upstream
> X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>
> Control: clone -1 -2
> Control: reassign -2 src:emacs 1:28.2+1-13
> Control: retitle -2 emacs: CVE-2023-28617
>
> Hi,
>
> The following vulnerability was published for org-mode (and emacs,
> will close tis bug).
>
> CVE-2023-28617[0]:
> | org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for
> | GNU Emacs allows attackers to execute arbitrary commands via a file
> | name or directory name that contains shell metacharacters.

All lisp files were dropped in org-mode/9.5.2+dfsh-5, and so this CVE is
fixed there; however, unfortunately this bug was not closed from that
changelog entry.

This CVE is also not present in the 9.6.6+dfsg-1~exp1 that I just
uploaded to experimental, but be honest I forgot about this bug when
uploading, and so I forgot to close this bug from the changelog as
instructed.  Sorry.

What is the correct way to proceed now?

Regards,
Nicholas

Back to linux.debian.bugs.dist | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#1033341: org-mode: CVE-2023-28617 Salvatore Bonaccorso <carnil@debian.org> - 2023-03-22 22:50 +0100
  Bug#1033341: org-mode: CVE-2023-28617 Nicholas D Steeves <sten@debian.org> - 2023-06-04 04:10 +0200
    Bug#1033341: org-mode: CVE-2023-28617 Salvatore Bonaccorso <carnil@debian.org> - 2023-06-04 07:40 +0200
    Bug#1033341: org-mode: CVE-2023-28617 David Bremner <david@tethera.net> - 2023-06-04 13:50 +0200
      Bug#1033341: org-mode: CVE-2023-28617 Salvatore Bonaccorso <carnil@debian.org> - 2023-06-04 14:40 +0200
        Bug#1033341: org-mode: CVE-2023-28617 David Bremner <david@tethera.net> - 2023-06-04 21:10 +0200
      Bug#1033341: org-mode: CVE-2023-28617 Nicholas D Steeves <sten@debian.org> - 2023-06-13 02:00 +0200

csiph-web