CVE-2024-53920

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-53920
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-53920.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-53920
Related
Published
2024-11-27T15:15:26Z
Modified
2025-01-14T12:17:31.116981Z
Summary
[none]
Details

In elisp-mode.el in GNU Emacs through 30.0.92, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)

References

Affected packages

Debian:11 / emacs

Package

Name
emacs
Purl
pkg:deb/debian/emacs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:27.*

1:27.1+1-3.1
1:27.1+1-3.1+deb11u1
1:27.1+1-3.1+deb11u2
1:27.1+1-3.1+deb11u3
1:27.1+1-3.1+deb11u4
1:27.1+1-3.1+deb11u5

1:28.*

1:28.1+1-1
1:28.1+1-2
1:28.1+1-2+m68k
1:28.1+1-3
1:28.1+1-4
1:28.2+1-1
1:28.2+1-2
1:28.2+1-3
1:28.2+1-4
1:28.2+1-5
1:28.2+1-6
1:28.2+1-7
1:28.2+1-8
1:28.2+1-9
1:28.2+1-10
1:28.2+1-11
1:28.2+1-12
1:28.2+1-13
1:28.2+1-14
1:28.2+1-15
1:28.2+1-16

1:29.*

1:29.1+1-1
1:29.1+1-2
1:29.1+1-3
1:29.1+1-4
1:29.1+1-5~bpo12+1
1:29.1+1-5
1:29.2+1-1
1:29.2+1-2~bpo12+1
1:29.2+1-2
1:29.3+1-1
1:29.3+1-2~bpo12+1
1:29.3+1-2
1:29.3+1-3~bpo12+1
1:29.3+1-3
1:29.4+1-1
1:29.4+1-2~bpo12+1
1:29.4+1-2
1:29.4+1-3
1:29.4+1-4~bpo12+1
1:29.4+1-4
1:29.4+1-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / emacs

Package

Name
emacs
Purl
pkg:deb/debian/emacs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:28.*

1:28.2+1-15
1:28.2+1-15+deb12u1
1:28.2+1-15+deb12u2
1:28.2+1-15+deb12u3
1:28.2+1-16

1:29.*

1:29.1+1-1
1:29.1+1-2
1:29.1+1-3
1:29.1+1-4
1:29.1+1-5~bpo12+1
1:29.1+1-5
1:29.2+1-1
1:29.2+1-2~bpo12+1
1:29.2+1-2
1:29.3+1-1
1:29.3+1-2~bpo12+1
1:29.3+1-2
1:29.3+1-3~bpo12+1
1:29.3+1-3
1:29.4+1-1
1:29.4+1-2~bpo12+1
1:29.4+1-2
1:29.4+1-3
1:29.4+1-4~bpo12+1
1:29.4+1-4
1:29.4+1-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / emacs

Package

Name
emacs
Purl
pkg:deb/debian/emacs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:28.*

1:28.2+1-15
1:28.2+1-16

1:29.*

1:29.1+1-1
1:29.1+1-2
1:29.1+1-3
1:29.1+1-4
1:29.1+1-5~bpo12+1
1:29.1+1-5
1:29.2+1-1
1:29.2+1-2~bpo12+1
1:29.2+1-2
1:29.3+1-1
1:29.3+1-2~bpo12+1
1:29.3+1-2
1:29.3+1-3~bpo12+1
1:29.3+1-3
1:29.4+1-1
1:29.4+1-2~bpo12+1
1:29.4+1-2
1:29.4+1-3
1:29.4+1-4~bpo12+1
1:29.4+1-4
1:29.4+1-5

Ecosystem specific

{
    "urgency": "not yet assigned"
}