CVE-2024-30205: High severity ibm cognos analytics vulnerability
GNU Emacs could provide weaker than expected security, caused by an issue with contents of remote files to be trusted in Org mode. A remote attacker could exploit this vulnerability to launch further attacks on the system.
Other sources
In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30205?
CVE-2024-30205 is classified as a medium severity vulnerability.
How do I fix CVE-2024-30205?
To mitigate CVE-2024-30205, upgrade to Emacs version 29.3 or later and Org Mode version 9.6.23 or later.
What are the affected versions associated with CVE-2024-30205?
CVE-2024-30205 affects Emacs versions prior to 29.3 and Org Mode versions prior to 9.6.23.
What does CVE-2024-30205 exploit?
CVE-2024-30205 exploits the trust placed in the contents of remote files in Emacs Org mode.
Which distributions are impacted by CVE-2024-30205?
CVE-2024-30205 impacts users of Emacs in Red Hat and Debian distributions prior to the specified versions.