First published: Mon Apr 05 2010(Updated: )
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
Credit: security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Emacs | =22.1 | |
GNU Emacs | =23.1 | |
GNU Emacs | =22.3 | |
GNU Emacs | =22.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0825 has been classified as a moderate severity vulnerability due to the potential for local users to exploit it.
To fix CVE-2010-0825, update to a patched version of GNU Emacs that addresses the file-permission checks.
CVE-2010-0825 affects GNU Emacs versions 22.1, 22.2, 22.3, and 23.1.
CVE-2010-0825 allows for a symlink attack that could let local users read, modify, or delete mailbox files.
No, CVE-2010-0825 is a local vulnerability, meaning it requires local access to exploit.