CVE-2014-3424
08.05.2014, 10:55
lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.
Vendor | Product | Version |
---|---|---|
gnu | emacs | 𝑥 ≤ 24.3 |
gnu | emacs | 20.0 |
gnu | emacs | 20.1 |
gnu | emacs | 20.2 |
gnu | emacs | 20.3 |
gnu | emacs | 20.4 |
gnu | emacs | 20.5 |
gnu | emacs | 20.6 |
gnu | emacs | 20.7 |
gnu | emacs | 21.1 |
gnu | emacs | 21.2 |
gnu | emacs | 21.2.1 |
gnu | emacs | 21.3 |
gnu | emacs | 21.3.1 |
gnu | emacs | 21.4 |
gnu | emacs | 22.1 |
gnu | emacs | 22.2 |
gnu | emacs | 22.3 |
gnu | emacs | 23.1 |
gnu | emacs | 23.2 |
gnu | emacs | 23.3 |
gnu | emacs | 23.4 |
gnu | emacs | 24.1 |
gnu | emacs | 24.2 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
emacs-snapshot |
| ||||||||||||||||||||||||||||||
emacs22 |
| ||||||||||||||||||||||||||||||
emacs23 |
| ||||||||||||||||||||||||||||||
emacs24 |
| ||||||||||||||||||||||||||||||
emacs25 |
| ||||||||||||||||||||||||||||||
xemacs21 |
| ||||||||||||||||||||||||||||||
xemacs21-packages |
|
References