CVE-2017-14482

UnknownEPSS 4.04%

Last modified

CVE-2017-14482 is a vulnerability of currently unknown severity. GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).. EPSS estimates a 4.04% chance of exploitation in the next 30 days.

Description

GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).

Metrics

EPSS Probability
4.04%

89.3th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
GnuEmacs<= 25.2
DebianDebian Linux8.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-14482?
GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell commands, related to an unsafe text/enriched extension in lisp/textmodes/enriched.el, and unsafe Gnus support for enriched and richtext inline MIME objects in lisp/gnus/mm-view.el. In particular, an Emacs user can be instantly compromised by reading a crafted email message (or Usenet news article).
How severe is CVE-2017-14482?
Severity scoring for CVE-2017-14482 is pending analysis. The EPSS model estimates a 4.04% probability of exploitation in the next 30 days.
How do I fix CVE-2017-14482?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-14482?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST