Source: emacs
Version: 1:29.4+1-6
Severity: grave
Tags: security upstream
Justification: user security hole
Forwarded: https://debbugs.gnu.org/66390
X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>

Hi,

The following vulnerability was published for emacs.

CVE-2025-1244[0]:
| A flaw was found in the Emacs text editor. Improper handling of
| custom "man" URI schemes allows attackers to execute arbitrary shell
| commands by tricking users into visiting a specially crafted website
| or an HTTP URL with a redirect.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-1244
    https://www.cve.org/CVERecord?id=CVE-2025-1244
[1] https://debbugs.gnu.org/66390
[2] 
https://git.savannah.gnu.org/cgit/emacs.git/commit/?id=820f0793f0b46448928905552726c1f1b999062f

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to