Amazon Linux 2 Security Advisory: ALAS-2023-1928
Advisory Release Date: 2023-01-30 16:03 Pacific
Advisory Updated Date: 2023-02-04 18:28 Pacific
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may use the "ctags *" command (suggested in the ctags documentation) in a situation where the current working directory has contents that depend on untrusted input. (CVE-2022-45939)
Affected Packages:
emacs
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update emacs to update your system.
aarch64:
emacs-27.2-4.amzn2.0.2.aarch64
emacs-lucid-27.2-4.amzn2.0.2.aarch64
emacs-nox-27.2-4.amzn2.0.2.aarch64
emacs-common-27.2-4.amzn2.0.2.aarch64
emacs-devel-27.2-4.amzn2.0.2.aarch64
emacs-debuginfo-27.2-4.amzn2.0.2.aarch64
i686:
emacs-27.2-4.amzn2.0.2.i686
emacs-lucid-27.2-4.amzn2.0.2.i686
emacs-nox-27.2-4.amzn2.0.2.i686
emacs-common-27.2-4.amzn2.0.2.i686
emacs-devel-27.2-4.amzn2.0.2.i686
emacs-debuginfo-27.2-4.amzn2.0.2.i686
noarch:
emacs-terminal-27.2-4.amzn2.0.2.noarch
emacs-filesystem-27.2-4.amzn2.0.2.noarch
src:
emacs-27.2-4.amzn2.0.2.src
x86_64:
emacs-27.2-4.amzn2.0.2.x86_64
emacs-lucid-27.2-4.amzn2.0.2.x86_64
emacs-nox-27.2-4.amzn2.0.2.x86_64
emacs-common-27.2-4.amzn2.0.2.x86_64
emacs-devel-27.2-4.amzn2.0.2.x86_64
emacs-debuginfo-27.2-4.amzn2.0.2.x86_64