PT-2000-1253 · Gnu · Emacs

Published

2000-04-18

·

Updated

2008-09-10

·

CVE-2000-0271

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Emacs version 20
Description The issue is related to the read-passwd and other Lisp functions in Emacs, which do not properly clear the history of recently typed keys. This allows an attacker to read unencrypted passwords.
Recommendations For Emacs version 20, consider disabling the read-passwd function until a patch is available to properly clear the key history and prevent unauthorized access to unencrypted passwords.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2000-0271

Affected Products

Emacs