{"api_version":"1","generated_at":"2026-07-23T10:57:36+00:00","cve":"CVE-2007-6109","urls":{"html":"https://cve.report/CVE-2007-6109","api":"https://cve.report/api/cve/CVE-2007-6109.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-6109","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-6109"},"summary":{"title":"CVE-2007-6109","description":"Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain \"emacs -batch -eval\" command line.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-12-07 11:46:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/27965","name":"http://secunia.com/advisories/27965","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SUSE Update for Multiple Packages - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:034","name":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:034","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Support / Security / Advisories /  / MDVSA-2008:034 | Mandriva","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/29420","name":"http://secunia.com/advisories/29420","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mac OS X Security Update Fixes Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://docs.info.apple.com/article.html?artnum=307562","name":"http://docs.info.apple.com/article.html?artnum=307562","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"About Security Update 2008-002","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html","name":"http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE Security Summary Report SUSE-SR:2008:003","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2007_25_sr.html","name":"http://www.novell.com/linux/security/advisories/2007_25_sr.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404 Page Not Found | SUSE","mime":"text/html","httpstatus":"404","archivestatus":"406"},{"url":"http://secunia.com/advisories/28838","name":"http://secunia.com/advisories/28838","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SUSE Update for Multiple Packages - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/30109","name":"http://secunia.com/advisories/30109","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ubuntu update for emacs - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.gentoo.org/show_bug.cgi?id=200297","name":"http://bugs.gentoo.org/show_bug.cgi?id=200297","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Bug 200297 - app-editors/emacs < 22.1-r3 Buffer overflow in format function (CVE-2007-6109)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://security.gentoo.org/glsa/glsa-200712-03.xml","name":"http://security.gentoo.org/glsa/glsa-200712-03.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Linux Documentation\n--\n  GNU Emacs: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html","name":"http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"APPLE-SA-2008-03-18 Security Update 2008-002","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/607-1/","name":"https://usn.ubuntu.com/607-1/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"USN-607-1: Emacs vulnerabilities | Ubuntu security notices","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38904","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38904","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/27984","name":"http://secunia.com/advisories/27984","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo update for emacs - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0924/references","name":"http://www.vupen.com/english/advisories/2008/0924/references","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-6109","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-6109","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"6109","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnu","cpe5":"emacs","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2007-6109","organization":"Red Hat","lastmodified":"2007-12-11","contributor":"Mark J Cox","statementText":"Red Hat does not consider this issue to be a security vulnerability since no trust boundary is crossed. The user must voluntarily interact with the attack mechanism to exploit this flaw, with the result being the ability to run code as themselves.","cve_year":"2007","cve_id":"6109","crc32":"c31f2bfe"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2007-6109","qid":"902235","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for emacs (9919)"},{"cve":"CVE-2007-6109","qid":"906311","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for emacs (9919-2)"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:54:26.839Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"27965","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27965"},{"name":"USN-607-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"https://usn.ubuntu.com/607-1/"},{"name":"27984","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27984"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.gentoo.org/show_bug.cgi?id=200297"},{"name":"ADV-2008-0924","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0924/references"},{"name":"SUSE-SR:2007:025","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://www.novell.com/linux/security/advisories/2007_25_sr.html"},{"name":"29420","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/29420"},{"name":"APPLE-SA-2008-03-18","tags":["vendor-advisory","x_refsource_APPLE","x_transferred"],"url":"http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html"},{"name":"emacs-unspecified-bo(38904)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38904"},{"name":"MDVSA-2008:034","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:034"},{"name":"30109","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/30109"},{"name":"GLSA-200712-03","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-200712-03.xml"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://docs.info.apple.com/article.html?artnum=307562"},{"name":"28838","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28838"},{"name":"SUSE-SR:2008:003","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-12-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain \"emacs -batch -eval\" command line."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-03T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"27965","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27965"},{"name":"USN-607-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"https://usn.ubuntu.com/607-1/"},{"name":"27984","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27984"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.gentoo.org/show_bug.cgi?id=200297"},{"name":"ADV-2008-0924","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0924/references"},{"name":"SUSE-SR:2007:025","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://www.novell.com/linux/security/advisories/2007_25_sr.html"},{"name":"29420","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/29420"},{"name":"APPLE-SA-2008-03-18","tags":["vendor-advisory","x_refsource_APPLE"],"url":"http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html"},{"name":"emacs-unspecified-bo(38904)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38904"},{"name":"MDVSA-2008:034","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:034"},{"name":"30109","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/30109"},{"name":"GLSA-200712-03","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-200712-03.xml"},{"tags":["x_refsource_CONFIRM"],"url":"http://docs.info.apple.com/article.html?artnum=307562"},{"name":"28838","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28838"},{"name":"SUSE-SR:2008:003","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-6109","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain \"emacs -batch -eval\" command line."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"27965","refsource":"SECUNIA","url":"http://secunia.com/advisories/27965"},{"name":"USN-607-1","refsource":"UBUNTU","url":"https://usn.ubuntu.com/607-1/"},{"name":"27984","refsource":"SECUNIA","url":"http://secunia.com/advisories/27984"},{"name":"http://bugs.gentoo.org/show_bug.cgi?id=200297","refsource":"CONFIRM","url":"http://bugs.gentoo.org/show_bug.cgi?id=200297"},{"name":"ADV-2008-0924","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0924/references"},{"name":"SUSE-SR:2007:025","refsource":"SUSE","url":"http://www.novell.com/linux/security/advisories/2007_25_sr.html"},{"name":"29420","refsource":"SECUNIA","url":"http://secunia.com/advisories/29420"},{"name":"APPLE-SA-2008-03-18","refsource":"APPLE","url":"http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html"},{"name":"emacs-unspecified-bo(38904)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/38904"},{"name":"MDVSA-2008:034","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDVSA-2008:034"},{"name":"30109","refsource":"SECUNIA","url":"http://secunia.com/advisories/30109"},{"name":"GLSA-200712-03","refsource":"GENTOO","url":"http://security.gentoo.org/glsa/glsa-200712-03.xml"},{"name":"http://docs.info.apple.com/article.html?artnum=307562","refsource":"CONFIRM","url":"http://docs.info.apple.com/article.html?artnum=307562"},{"name":"28838","refsource":"SECUNIA","url":"http://secunia.com/advisories/28838"},{"name":"SUSE-SR:2008:003","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-6109","datePublished":"2007-12-07T11:00:00.000Z","dateReserved":"2007-11-23T00:00:00.000Z","dateUpdated":"2024-08-07T15:54:26.839Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-12-07 11:46:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gnu:emacs:*:*:*:*:*:*:*:*","matchCriteriaId":"DD426FD8-4155-4FC5-8114-266BD0FCA841"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"6109","Ordinal":"1","Title":"CVE-2007-6109","CVE":"CVE-2007-6109","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"6109","Ordinal":"1","NoteData":"Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain \"emacs -batch -eval\" command line.","Type":"Description","Title":"CVE-2007-6109"},{"CveYear":"2007","CveId":"6109","Ordinal":"2","NoteData":"2007-12-07","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"6109","Ordinal":"3","NoteData":"2018-10-03","Type":"Other","Title":"Modified"}]}}}