GNU Emacs Multiple Insecure Temporary File Handling Vulnerabilities
BID:67253
Info
GNU Emacs Multiple Insecure Temporary File Handling Vulnerabilities
| Bugtraq ID: | 67253 |
| Class: | Design Error |
| CVE: |
CVE-2014-3421 CVE-2014-3422 CVE-2014-3423 CVE-2014-3424 |
| Remote: | No |
| Local: | Yes |
| Published: | May 05 2014 12:00AM |
| Updated: | Jun 11 2014 05:12AM |
| Credit: | Steve Kemp |
| Vulnerable: |
MandrakeSoft Enterprise Server 5 x86_64 MandrakeSoft Enterprise Server 5 GNU Emacs 23.4 GNU Emacs 23.3 GNU Emacs 23.2 GNU Emacs 23.1 |
| Not Vulnerable: | |
Discussion
GNU Emacs Multiple Insecure Temporary File Handling Vulnerabilities
GNU Emacs is prone to multiple insecure temporary file-handling vulnerabilities.
An attacker with local access could potentially exploit these issues to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
GNU Emacs is prone to multiple insecure temporary file-handling vulnerabilities.
An attacker with local access could potentially exploit these issues to perform symbolic-link attacks, overwriting arbitrary files in the context of the affected application.
Exploit / POC
GNU Emacs Multiple Insecure Temporary File Handling Vulnerabilities
An attacker can use readily available commands to exploit these issues.
An attacker can use readily available commands to exploit these issues.
Solution / Fix
GNU Emacs Multiple Insecure Temporary File Handling Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GNU Emacs Multiple Insecure Temporary File Handling Vulnerabilities
References:
References:
- Emacs Product Page (GNU)