CVE-2024-30203: Is CVE-2024-30203 bogus? (Emacs)
GNU Emacs could provide weaker than expected security, caused by an issue with treating inline MIME contents as trusted. A remote attacker could exploit this vulnerability to launch further attacks on the system.
Other sources
In Emacs before 29.3, Gnus treats inline MIME contents as trusted.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30203?
CVE-2024-30203 has been classified with a moderate severity level due to its potential to allow exploitation through trusted inline MIME content.
How do I fix CVE-2024-30203?
To remediate CVE-2024-30203, upgrade Emacs to version 29.3 or later depending on your distribution.
Which versions of Emacs are affected by CVE-2024-30203?
Emacs versions prior to 29.3 are affected by CVE-2024-30203.
Is Gnus specifically impacted by CVE-2024-30203?
Yes, Gnus in Emacs before version 29.3 has vulnerabilities related to treating inline MIME contents as trusted.
What impact does CVE-2024-30203 have on email security?
CVE-2024-30203 may lead to the risk of executing malicious content within emails due to improper trust in inline MIME handling.