VDB
BDU%3A2024-10771
BDU%3A2024-10771
PUBLISHED
CVSS 10 CRITICAL
Уязвимость функции elisp-completion-at-point() и elisp-flymake-byte-compile() режима ELisp текстового редактора EMACS, позволяющая нарушителю выполнить произвольный код
Risk Scores
CVSS 2.0
10
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., The GNU Project, ООО «НЦПР» | Red Hat Enterprise Linux, EMACS, МСВСфера |
Timeline
- Dec 5, 2024 CVE Published
- Nov 19, 2025 CVE Updated
References
- https://vuldb.com/ru/?id.286260 url
- https://access.redhat.com/security/cve/cve-2024-53920 url
- https://eshelyaron.com/posts/2024-11-27-emacs-aritrary-code-execution-and-how-to-avoid-it.html url
- https://git.savannah.gnu.org/cgit/emacs.git/tag/?h=emacs-30.0.92 url
- https://git.savannah.gnu.org/cgit/emacs.git/tree/ChangeLog.4 url
- https://news.ycombinator.com/item?id=42256409 url
- https://yhetil.org/emacs/CAFXAjY5f4YfHAtZur1RAqH34UbYU56_t6t2Er0YEh1Sb7-W=hg%40mail.gmail.com/ url
- https://errata.msvsphere-os.ru/definition/9/INFCSA-2025:9448?lang=ru advisory