PT-2003-2177 · Gnu · Emacs

Georgi Guninski

·

Published

2003-12-31

·

Updated

2011-03-08

·

CVE-2003-1232

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Emacs version 21.2.1
Description The issue allows user-assisted attackers to execute arbitrary commands because it does not prompt or warn the user before executing Lisp code in the local variables section of a text file. This can be demonstrated using the mode-name variable.
Recommendations For Emacs version 21.2.1, consider disabling the execution of Lisp code in the local variables section of text files until a patch is available. Restrict access to sensitive features that may be exploited through this issue to minimize the risk of arbitrary command execution.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-1232

Affected Products

Emacs