GNU Emacs '.flc' File Processing Vulnerability
BID:29176
Info
GNU Emacs '.flc' File Processing Vulnerability
| Bugtraq ID: | 29176 |
| Class: | Design Error |
| CVE: |
CVE-2008-2142 |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2008 12:00AM |
| Updated: | Apr 13 2015 10:10PM |
| Credit: | Morten Welinder |
| Vulnerable: |
XEmacs Development Team XEmacs 21.5 XEmacs Development Team XEmacs 21.4 SuSE SUSE Linux Enterprise Server 9 SuSE SUSE Linux Enterprise Server 8 SuSE SUSE Linux Enterprise Server 10 SP2 SuSE SUSE Linux Enterprise Server 10 SP1 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise SDK 10.SP1 SuSE SUSE Linux Enterprise SDK 10 SP2 SuSE SUSE Linux Enterprise SDK 10 SP1 SuSE SUSE Linux Enterprise SDK 10 SuSE Suse Linux Enterprise Desktop 10 SP2 SuSE Suse Linux Enterprise Desktop 10 SP1 SuSE Suse Linux Enterprise Desktop 10 SuSE SUSE Linux Enterprise 10 SP1 DEBUGINFO SuSE Linux Openexchange Server SuSE Linux Desktop 10 SuSE Linux 10.1 x86-64 SuSE Linux 10.1 x86 SuSE Linux 10.1 ppc SuSE Linux 10.0 x86-64 SuSE Linux 10.0 x86 SuSE Linux 10.0 ppc S.u.S.E. UnitedLinux 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. SUSE Linux Enterprise Server RT Solution 10 0 S.u.S.E. openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. openSUSE 10.1 S.u.S.E. Open-Enterprise-Server 1 S.u.S.E. Open-Enterprise-Server 0 S.u.S.E. Novell Linux POS 9 S.u.S.E. Novell Linux Desktop SDK 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 10.2 X86 64 S.u.S.E. Linux Professional 10.2 S.u.S.E. Linux Professional 10.1 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 10.2 X86 64 S.u.S.E. Linux Personal 10.2 S.u.S.E. Linux Personal 10.1 S.u.S.E. Linux Office Server rPath rPath Linux 1 Mandriva Linux Mandrake 2008.1 x86_64 Mandriva Linux Mandrake 2008.1 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 GNU Emacs 21.3.1 Gentoo Linux |
| Not Vulnerable: | |
Discussion
GNU Emacs '.flc' File Processing Vulnerability
Emacs processes fast-lock files in an insecure manner.
An attacker could exploit this issue to execute arbitrary code with the privileges of the user running the vulnerable application.
This issue affects Emacs 21.3.1; other versions may also be vulnerable.
Emacs processes fast-lock files in an insecure manner.
An attacker could exploit this issue to execute arbitrary code with the privileges of the user running the vulnerable application.
This issue affects Emacs 21.3.1; other versions may also be vulnerable.
Exploit / POC
GNU Emacs '.flc' File Processing Vulnerability
An attacker could exploit this issue by crafting fast-lock files with malicious Lisp code.
An attacker could exploit this issue by crafting fast-lock files with malicious Lisp code.
Solution / Fix
GNU Emacs '.flc' File Processing Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
GNU Emacs '.flc' File Processing Vulnerability
References:
References:
- .flc files can run arbitrary code automatically (XEmacs)
- Emacs Product Page (GNU)
- Emacs Security bug (Morten Welinder)
- XEmacs Homepage (XEmacs)