Skip to main content

Threats Tagged 'cve-2024-39331'

View all threats tagged with 'cve-2024-39331'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2024-39331

Threats Tagged 'cve-2024-39331'

Click on any threat for detailed analysis and mitigation recommendations

0

This advisory addresses multiple security vulnerabilities in GNU Emacs as packaged for Red Hat Enterprise Linux 8. The issues include Gnus treating inline MIME contents as trusted, Org mode considering contents of remote files as trusted, and unsafe evaluation of arbitrary Elisp code via org-link-expand-abbrev. These vulnerabilities could lead to execution of untrusted code or improper trust assumptions in Emacs features. Red Hat has released updated packages to fix these issues in Emacs 26.1-12.el8_10 for various architectures.

Join the discussion
0

A moderate severity vulnerability (CVE-2024-39331) in GNU Emacs affects the org-link-expand-abbrev function, which could lead to the evaluation of arbitrary unsafe Elisp code. This issue is addressed by a security update released by Red Hat for their Enterprise Linux 8.8 Extended Update Support versions. The vulnerability involves unsafe code evaluation in Emacs's scripting language (Elisp).

Join the discussion
CVE-2024-39331: n/aCVE-2024-39331
0

In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: cve-2024-39331
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses