CVE-2014-3422
08.05.2014, 10:55
lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.
| Vendor | Product | Version |
|---|---|---|
| gnu | emacs | 𝑥 ≤ 24.3 |
| gnu | emacs | 20.0 |
| gnu | emacs | 20.1 |
| gnu | emacs | 20.2 |
| gnu | emacs | 20.3 |
| gnu | emacs | 20.4 |
| gnu | emacs | 20.5 |
| gnu | emacs | 20.6 |
| gnu | emacs | 20.7 |
| gnu | emacs | 21.1 |
| gnu | emacs | 21.2 |
| gnu | emacs | 21.2.1 |
| gnu | emacs | 21.3 |
| gnu | emacs | 21.3.1 |
| gnu | emacs | 21.4 |
| gnu | emacs | 22.1 |
| gnu | emacs | 22.2 |
| gnu | emacs | 22.3 |
| gnu | emacs | 23.1 |
| gnu | emacs | 23.2 |
| gnu | emacs | 23.3 |
| gnu | emacs | 23.4 |
| gnu | emacs | 24.1 |
| gnu | emacs | 24.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| emacs-snapshot |
| ||||||||||||||||||||||||||||||
| emacs22 |
| ||||||||||||||||||||||||||||||
| emacs23 |
| ||||||||||||||||||||||||||||||
| emacs24 |
| ||||||||||||||||||||||||||||||
| emacs25 |
| ||||||||||||||||||||||||||||||
| xemacs21 |
| ||||||||||||||||||||||||||||||
| xemacs21-packages |
|
References