lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.
2014-05-08T10:55:05.217
2025-04-12T10:46:40.837
Deferred
CVSSv2: 3.3 (LOW)
AV:L/AC:M/Au:N/C:N/I:P/A:P
3.4
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | mageia_project | mageia | 3 | Yes |
Operating System | mageia_project | mageia | 4 | Yes |
Application | gnu | emacs | ≤ 24.3 | Yes |
Application | gnu | emacs | 20.0 | Yes |
Application | gnu | emacs | 20.1 | Yes |
Application | gnu | emacs | 20.2 | Yes |
Application | gnu | emacs | 20.3 | Yes |
Application | gnu | emacs | 20.4 | Yes |
Application | gnu | emacs | 20.5 | Yes |
Application | gnu | emacs | 20.6 | Yes |
Application | gnu | emacs | 20.7 | Yes |
Application | gnu | emacs | 21 | Yes |
Application | gnu | emacs | 21.1 | Yes |
Application | gnu | emacs | 21.2 | Yes |
Application | gnu | emacs | 21.2.1 | Yes |
Application | gnu | emacs | 21.3 | Yes |
Application | gnu | emacs | 21.3.1 | Yes |
Application | gnu | emacs | 21.4 | Yes |
Application | gnu | emacs | 22.1 | Yes |
Application | gnu | emacs | 22.2 | Yes |
Application | gnu | emacs | 22.3 | Yes |
Application | gnu | emacs | 23.1 | Yes |
Application | gnu | emacs | 23.2 | Yes |
Application | gnu | emacs | 23.3 | Yes |
Application | gnu | emacs | 23.4 | Yes |
Application | gnu | emacs | 24.1 | Yes |
Application | gnu | emacs | 24.2 | Yes |