PT-2017-10957 · Gnu · Gnu Emacs
Published
2017-10-31
·
Updated
2017-11-27
·
CVE-2017-1000383
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GNU Emacs version 25.3.1
Description
The issue concerns GNU Emacs ignoring umask when creating a backup save file, resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.
Recommendations
For GNU Emacs version 25.3.1, consider adjusting the umask setting manually to ensure backup files are created with the intended permissions until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnu Emacs