CVE-2008-1694: Medium severity gnu emacs vulnerability
Description of problem: vcdiff script writes to a predictable tmp file. This could be used for attack by malicious user.
Other sources
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-1694?
CVE-2008-1694 is categorized as a medium severity vulnerability due to its potential for local file overwrite attacks.
How do I fix CVE-2008-1694?
To mitigate CVE-2008-1694, users should update to a patched version of GNU Emacs that resolves the symlink vulnerability.
Who is affected by CVE-2008-1694?
CVE-2008-1694 affects local users of GNU Emacs versions 20.7 through 22.1.50 when used with SCCS.
What type of attack is associated with CVE-2008-1694?
CVE-2008-1694 involves a symlink attack that allows local users to overwrite arbitrarily chosen files.
Is CVE-2008-1694 a remote exploit?
No, CVE-2008-1694 is not a remote exploit; it requires local access to the system to be effective.