PT-2007-4143 · Gnu · Emacs
Published
2007-06-21
·
Updated
2008-09-05
·
CVE-2007-2833
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Emacs version 21
Description
The issue allows user-assisted attackers to cause a denial of service, resulting in a crash, by using certain crafted images. This has been demonstrated using a GIF image in vm mode and is related to image size calculation.
Recommendations
For Emacs version 21, consider avoiding the use of crafted images, especially GIF images in vm mode, until a fix is available. As a temporary workaround, restrict the processing of images to prevent potential crashes.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Emacs