Debian Security Advisory

DSA-3970-1 emacs24 -- security update

Date Reported:
12 Sep 2017
Affected Packages:
emacs24
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 875448.
In Mitre's CVE dictionary: CVE-2017-14482.
More information:

Charles A. Roelli discovered that Emacs is vulnerable to arbitrary code execution when rendering text/enriched MIME data (e.g. when using Emacs-based mail clients).

For the oldstable distribution (jessie), this problem has been fixed in version 24.4+1-5+deb8u1.

For the stable distribution (stretch), this problem has been fixed in version 24.5+1-11+deb9u1.

We recommend that you upgrade your emacs24 packages.