PT-2000-1252 · Gnu · Emacs
Published
2000-04-18
·
Updated
2008-09-10
·
CVE-2000-0270
CVSS v2.0
3.6
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Emacs version 20
Description
The issue concerns the make-temp-name Lisp function, which generates temporary files with predictable names. This predictability allows attackers to potentially conduct a symlink attack.
Recommendations
For Emacs version 20, consider modifying the make-temp-name function to generate unpredictable temporary file names until a patch is available. As a temporary workaround, restrict access to the temporary file directory to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Emacs