CVE-2008-2142: Medium severity gnu emacs vulnerability
Published May 12, 2008
·Updated
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.
Affected Software
2 affected components
GNU Emacs=21.3.1
GNU XEmacs
Event History
May 12, 2008
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2142?
CVE-2008-2142 has a high severity rating due to the potential for arbitrary code execution.
2
How do I fix CVE-2008-2142?
To fix CVE-2008-2142, upgrade to a patched version of Emacs or XEmacs that disables the automatic loading of .flc files.
3
Which versions of Emacs are affected by CVE-2008-2142?
Emacs version 21.3.1 is specifically affected by CVE-2008-2142.
4
Can CVE-2008-2142 be exploited remotely?
CVE-2008-2142 requires user interaction to exploit, making it a user-assisted attack.
5
What are the implications of exploiting CVE-2008-2142?
Exploiting CVE-2008-2142 can lead to arbitrary code execution, compromising the affected user's system.