emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. References: https://www.openwall.com/lists/oss-security/2023/03/08/2 http://www.openwall.com/lists/oss-security/2023/03/09/1 Upstream patch: http://git.savannah.gnu.org/cgit/emacs.git/commit/?h=emacs-29&id=3c1693d08b0a71d40a77e7b40c0ebc42dca2d2cc
Created emacs tracking bugs for this issue: Affects: fedora-all [bug 2176474]