PT-2014-5309 · Gnu+1 · Gnu Emacs+1

Steve Kemp

·

Published

2014-05-08

·

Updated

2024-06-15

·

CVE-2014-3422

CVSS v2.0

3.3

Low

VectorAV:L/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions GNU Emacs versions prior to 24.4
Description The issue allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.
Recommendations For GNU Emacs versions prior to 24.4, update to version 24.4 or later to resolve the issue.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3422
MGASA-2014-0250
OPENSUSE-SU-2024:10469-1

Affected Products

Gnu Emacs
Suse