PT-2003-2177 · Gnu · Emacs

Georgi Guninski

·

Publicado

2003-12-31

·

Atualizado

2011-03-08

·

CVE-2003-1232

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Emacs version 21.2.1
Description The issue allows user-assisted attackers to execute arbitrary commands because it does not prompt or warn the user before executing Lisp code in the local variables section of a text file. This can be demonstrated using the mode-name variable.
Recommendations For Emacs version 21.2.1, consider disabling the execution of Lisp code in the local variables section of text files until a patch is available. Restrict access to sensitive features that may be exploited through this issue to minimize the risk of arbitrary command execution.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-1232

Produtos afetados

Emacs