CVE-2012-3479

EUVD-2012-3435
lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
Affected Products (NVD)
VendorProductVersion
gnuemacs
23.2
gnuemacs
23.3
gnuemacs
23.4
gnuemacs
24.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
emacs-snapshot
hardy
ignored
lucid
ignored
natty
ignored
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
emacs21
hardy
ignored
lucid
dne
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
emacs22
hardy
ignored
lucid
not-affected
natty
dne
oneiric
dne
precise
dne
quantal
dne
raring
dne
saucy
dne
emacs23
hardy
dne
lucid
not-affected
natty
ignored
oneiric
Fixed 23.3+1-1ubuntu4.1
released
precise
Fixed 23.3+1-1ubuntu9.1
released
quantal
Fixed 23.4+1-4ubuntu1
released
raring
Fixed 23.4+1-4ubuntu1
released
saucy
Fixed 23.4+1-4ubuntu1
released
emacs24
hardy
dne
lucid
dne
natty
dne
oneiric
dne
precise
dne
quantal
Fixed 24.1+1-2ubuntu3
released
raring
Fixed 24.1+1-2ubuntu3
released
saucy
Fixed 24.1+1-2ubuntu3
released
xemacs21
hardy
ignored
lucid
not-affected
natty
not-affected
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected