Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1148727

Bug#1033341: org-mode: CVE-2023-28617

From Salvatore Bonaccorso <carnil@debian.org>
Newsgroups linux.debian.bugs.dist, linux.debian.maint.emacsen
Subject Bug#1033341: org-mode: CVE-2023-28617
Date 2023-06-04 14:40 +0200
Message-ID <GCVbz-dBDu-3@gated-at.bofh.it> (permalink)
References (2 earlier) <GCLlT-duIa-1@gated-at.bofh.it> <Gcevg-env1-3@gated-at.bofh.it> <GCUpb-dB5l-1@gated-at.bofh.it> <Gcevg-env1-3@gated-at.bofh.it> <GCUpb-dB5l-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


Hi David,

On Sun, Jun 04, 2023 at 08:34:18AM -0300, David Bremner wrote:
> Nicholas D Steeves <sten@debian.org> writes:
> 
> > fixed 1033341 org/mode/9.5.2+dfsh-5
> > fixed 1033341 org-mode/9.6.6+dfsg-1~exp1
> > thanks
> 
> Are you sure about that? It depends on emacs 28.2, which afaik has the
> vulnerable org-mode embedded. I guess it's a question of interpretation,
> but the vulnerability is still there after installing the package.

For src:emacs the respective bug is in #1033342.

But this is why I as well mentioned that for org-mode this tecnically
would need a per suite "unimportant" tracking in the security-tracker
(as the source still affected up to < 9.6.6+dfsg-1~exp1, but not the
resulting binary packages).

Looking at https://security-tracker.debian.org/tracker/CVE-2023-28617
I think we should be fine for bookworm already, correct?

(For bullseye the issue is no-dsa and could be fixed with respective
updates in a point release).

Regards,
Salvatore

Back to linux.debian.bugs.dist | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#1033341: org-mode: CVE-2023-28617 Salvatore Bonaccorso <carnil@debian.org> - 2023-03-22 22:50 +0100
  Bug#1033341: org-mode: CVE-2023-28617 Nicholas D Steeves <sten@debian.org> - 2023-06-04 04:10 +0200
    Bug#1033341: org-mode: CVE-2023-28617 Salvatore Bonaccorso <carnil@debian.org> - 2023-06-04 07:40 +0200
    Bug#1033341: org-mode: CVE-2023-28617 David Bremner <david@tethera.net> - 2023-06-04 13:50 +0200
      Bug#1033341: org-mode: CVE-2023-28617 Salvatore Bonaccorso <carnil@debian.org> - 2023-06-04 14:40 +0200
        Bug#1033341: org-mode: CVE-2023-28617 David Bremner <david@tethera.net> - 2023-06-04 21:10 +0200
      Bug#1033341: org-mode: CVE-2023-28617 Nicholas D Steeves <sten@debian.org> - 2023-06-13 02:00 +0200

csiph-web