CVE-2007-5795: Medium severity GNU Emacs vulnerability
The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5795?
CVE-2007-5795 is considered a moderate severity vulnerability due to its potential to allow user-assisted attackers to modify critical program variables.
How do I fix CVE-2007-5795?
To fix CVE-2007-5795, upgrade Emacs to version 22.2 or later, where the vulnerability has been addressed.
What versions of Emacs are affected by CVE-2007-5795?
CVE-2007-5795 affects Emacs versions prior to 22.2.
What does CVE-2007-5795 allow an attacker to do?
CVE-2007-5795 allows user-assisted attackers to bypass intended restrictions on local variables in Emacs.
Is Debian Linux vulnerable to CVE-2007-5795?
Debian Linux is not vulnerable to CVE-2007-5795 as the vulnerability specifically pertains to certain versions of Emacs.