CVE-2012-3479

lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
VendorProductVersion
gnuemacs
23.2
gnuemacs
23.3
gnuemacs
23.4
gnuemacs
24.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
emacs-snapshot
saucy
dne
raring
dne
quantal
dne
precise
dne
oneiric
dne
natty
ignored
lucid
ignored
hardy
ignored
emacs21
saucy
dne
raring
dne
quantal
dne
precise
dne
oneiric
dne
natty
dne
lucid
dne
hardy
ignored
emacs22
saucy
dne
raring
dne
quantal
dne
precise
dne
oneiric
dne
natty
dne
lucid
not-affected
hardy
ignored
emacs23
saucy
Fixed 23.4+1-4ubuntu1
released
raring
Fixed 23.4+1-4ubuntu1
released
quantal
Fixed 23.4+1-4ubuntu1
released
precise
Fixed 23.3+1-1ubuntu9.1
released
oneiric
Fixed 23.3+1-1ubuntu4.1
released
natty
ignored
lucid
not-affected
hardy
dne
emacs24
saucy
Fixed 24.1+1-2ubuntu3
released
raring
Fixed 24.1+1-2ubuntu3
released
quantal
Fixed 24.1+1-2ubuntu3
released
precise
dne
oneiric
dne
natty
dne
lucid
dne
hardy
dne
xemacs21
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
lucid
not-affected
hardy
ignored