CVE-2023-2491

A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-latex.el can result in arbitrary command execution. This CVE exists because of a CVE-2023-28617 security regression for the emacs package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnu:emacs:26.1-9.el8:*:*:*:*:*:*:*
cpe:2.3:a:gnu:emacs:27.2-8.el9:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:9.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:9.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.8:*:*:*:*:*:*:*

History

21 Nov 2024, 07:58

Type Values Removed Values Added
References () https://access.redhat.com/errata/RHSA-2023:2626 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2023:2626 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2023:3104 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2023:3104 - Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2023-2491 - Third Party Advisory () https://access.redhat.com/security/cve/CVE-2023-2491 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2192873 - Issue Tracking, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2192873 - Issue Tracking, Third Party Advisory

25 May 2023, 17:25

Type Values Removed Values Added
First Time Redhat enterprise Linux
Redhat
Gnu
Redhat enterprise Linux Server Tus
Redhat enterprise Linux Server Aus
Redhat enterprise Linux Eus
Gnu emacs
References (MISC) https://access.redhat.com/security/cve/CVE-2023-2491 - (MISC) https://access.redhat.com/security/cve/CVE-2023-2491 - Third Party Advisory
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2192873 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2192873 - Issue Tracking, Third Party Advisory
References (MISC) https://access.redhat.com/errata/RHSA-2023:3104 - (MISC) https://access.redhat.com/errata/RHSA-2023:3104 - Third Party Advisory
References (MISC) https://access.redhat.com/errata/RHSA-2023:2626 - (MISC) https://access.redhat.com/errata/RHSA-2023:2626 - Third Party Advisory
CPE cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:8.8:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:gnu:emacs:26.1-9.el8:*:*:*:*:*:*:*
cpe:2.3:a:gnu:emacs:27.2-8.el9:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:9.2:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_eus:9.2:*:*:*:*:*:*:*
CWE CWE-77
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

17 May 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-17 22:15

Updated : 2026-06-17 05:52


NVD link : CVE-2023-2491

Mitre link : CVE-2023-2491

CVE.ORG link : CVE-2023-2491


JSON object : View

Products Affected

gnu

  • emacs

redhat

  • enterprise_linux_server_aus
  • enterprise_linux_eus
  • enterprise_linux_server_tus
  • enterprise_linux
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')