lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
21 Nov 2024, 02:08
Type | Values Removed | Values Added |
---|---|---|
References | () http://advisories.mageia.org/MGASA-2014-0250.html - | |
References | () http://debbugs.gnu.org/cgi/bugreport.cgi?bug=17428#8 - | |
References | () http://lists.gnu.org/archive/html/emacs-diffs/2014-05/msg00057.html - | |
References | () http://openwall.com/lists/oss-security/2014/05/07/7 - | |
References | () http://www.mandriva.com/security/advisories?name=MDVSA-2015:117 - |
Information
Published : 2014-05-08 10:55
Updated : 2024-11-21 02:08
NVD link : CVE-2014-3423
Mitre link : CVE-2014-3423
CVE.ORG link : CVE-2014-3423
JSON object : View
Products Affected
mageia_project
- mageia
gnu
- emacs
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')