CVE-2005-0100: High severity GNU Emacs vulnerability
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0100?
CVE-2005-0100 is considered to have a high severity level due to the potential for arbitrary code execution.
How do I fix CVE-2005-0100?
To mitigate CVE-2005-0100, upgrade to a patched version of Emacs or XEmacs that resolves the format string vulnerability.
Which versions are affected by CVE-2005-0100?
CVE-2005-0100 affects GNU Emacs versions 20.x, 21.3 and XEmacs versions up to and including 21.4.
What is a format string vulnerability in the context of CVE-2005-0100?
A format string vulnerability allows an attacker to manipulate the format string used in functions, potentially leading to arbitrary code execution.
Can CVE-2005-0100 be exploited by local attackers?
No, CVE-2005-0100 is primarily an issue exploited through remote malicious POP3 servers.