CVE-2022-45939: Critical vulnerability in GNU Emacs Editor
A critical security flaw in a family of text editors GNU Emacs could be exploited by a remote adversary to perform arbitrary commands on the system. The flaw, tracked as CVE-2022-45939 affects GNU Emacs through 28.2.
GNU Emacs is a powerful, customizable, self-documenting text editor. It provides special code editing features, a scripting language (elisp), and the capability to read e-mail and news.
GNU Emacs could allow a remote attacker to execute arbitrary commands on the system, caused by using the system C library function in its implementation of the ctags program by lib-src/etags.c. By using shell metacharacters in the name of a source-code file, an attacker could exploit CVE-2022-45939 to execute arbitrary commands on the system.
In light of the critical nature of the vulnerability, users are recommended to update to the latest version as soon as it is available to mitigate possible threats.