oss-sec mailing list archives
Re: Is CVE-2024-30203 bogus? (Emacs)
From: Ihor Radchenko <yantar92 () posteo net>
Date: Mon, 08 Apr 2024 18:44:21 +0000
Sean Whitton <spwhitton () spwhitton name> writes:
The description for CVE-2024-30203 is In Emacs before 29.3, Gnus treats inline MIME contents as trusted.
Before Emacs 29.3, there was no concept of trusted or untrusted content in Emacs. We introduced it specifically to control whether we allow running LaTeX on the contents of a given buffer. (And even in Emacs 29.3, the concept of untrusted contents is not yet official) So, at least the title is misleading.
and for CVE-2024-30204 is In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
This is closer to what was happening. Note that LaTeX preview itself was not a problem. The problem was that we executed actual latex program without user query with input taken from buffer text to generate the previews (using the default settings). LaTeX input can be specifically constructed to cause DOS when using LaTeX compiler, which is especially dangerous when the input is coming from emails. Also, only GNUS and MUA clients re-using gnus libs (at least, notmuch and mu4e) were affected. Not rmail, AFAIK.
... I think it's the first one -- can you confirm?
I hope that the above clarified things. -- Ihor Radchenko // yantar92, Org mode contributor, Learn more about Org mode at <https://orgmode.org/>. Support Org development at <https://liberapay.com/org-mode>, or support my work at <https://liberapay.com/yantar92>
Current thread:
- Is CVE-2024-30203 bogus? (Emacs) Sean Whitton (Apr 08)
- Re: Is CVE-2024-30203 bogus? (Emacs) Eli Zaretskii (Apr 08)
- Re: Is CVE-2024-30203 bogus? (Emacs) Max Nikulin (Apr 08)
- Re: Is CVE-2024-30203 bogus? (Emacs) Ihor Radchenko (Apr 08)
- Re: Is CVE-2024-30203 bogus? (Emacs) Sean Whitton (Apr 10)
- Re: Is CVE-2024-30203 bogus? (Emacs) Ihor Radchenko (Apr 10)
- Re: Re: Is CVE-2024-30203 bogus? (Emacs) Salvatore Bonaccorso (Apr 10)
- Re: Is CVE-2024-30203 bogus? (Emacs) Max Nikulin (Apr 10)
- Re: Is CVE-2024-30203 bogus? (Emacs) Sean Whitton (Apr 11)
- Re: Re: Is CVE-2024-30203 bogus? (Emacs) Sean Whitton (Apr 11)
- Re: Is CVE-2024-30203 bogus? (Emacs) Max Nikulin (Apr 11)
- Re: Is CVE-2024-30203 bogus? (Emacs) Sean Whitton (Apr 10)
- Re: Is CVE-2024-30203 bogus? (Emacs) Eli Zaretskii (Apr 08)