PT-2000-1251 · Gnu · Emacs
Published
2000-04-18
·
Updated
2008-09-10
·
CVE-2000-0269
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Emacs version 20
Description
The issue is related to improper permission settings for a slave PTY device when starting a new subprocess. This allows local users to read or modify communications between Emacs and the subprocess.
Recommendations
For Emacs version 20, update to a version where this issue is fixed, as the current version does not properly secure subprocess communications.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Emacs