CVE-2008-1694

vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.6 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
VendorProductVersion
gnuemacs
20.7
gnuemacs
21.1
gnuemacs
21.2
gnuemacs
21.3
gnuemacs
21.4
gnusccs
*
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
xemacs21
bullseye
21.4.24-9
fixed
etch
no-dsa
bookworm
21.4.24-11
fixed
sid
21.4.24-12
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
emacs21
karmic
dne
jaunty
not-affected
intrepid
not-affected
hardy
Fixed 21.4a+1-5.3ubuntu1.1
released
gutsy
Fixed 21.4a+1-5ubuntu4.1
released
feisty
Fixed 21.4a+1-2ubuntu1.2
released
dapper
Fixed 21.4a-3ubuntu2.2
released
emacs22
karmic
Fixed 22.2-0ubuntu2
released
jaunty
Fixed 22.2-0ubuntu2
released
intrepid
Fixed 22.2-0ubuntu2
released
hardy
Fixed 22.1-0ubuntu10.1
released
gutsy
Fixed 22.1-0ubuntu5.2
released
feisty
dne
dapper
dne
xemacs21
karmic
not-affected
jaunty
not-affected
intrepid
not-affected
hardy
Fixed 21.4.21-1ubuntu3.1
released
gutsy
Fixed 21.4.20-1.1ubuntu0.1
released
feisty
Fixed 21.4.19-2ubuntu0.1
released
dapper
Fixed 21.4.18-1ubuntu1.1
released