First published: Thu May 08 2014(Updated: )
lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mageia | =3 | |
Mageia | =4 | |
Emacs | <=24.3 | |
Emacs | =20.0 | |
Emacs | =20.1 | |
Emacs | =20.2 | |
Emacs | =20.3 | |
Emacs | =20.4 | |
Emacs | =20.5 | |
Emacs | =20.6 | |
Emacs | =20.7 | |
Emacs | =21 | |
Emacs | =21.1 | |
Emacs | =21.2 | |
Emacs | =21.2.1 | |
Emacs | =21.3 | |
Emacs | =21.3.1 | |
Emacs | =21.4 | |
Emacs | =22.1 | |
Emacs | =22.2 | |
Emacs | =22.3 | |
Emacs | =23.1 | |
Emacs | =23.2 | |
Emacs | =23.3 | |
Emacs | =23.4 | |
Emacs | =24.1 | |
Emacs | =24.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-3421 is considered moderate due to its potential for local users to overwrite arbitrary files.
To fix CVE-2014-3421, update GNU Emacs to a version later than 24.3 or apply a patch that addresses the symlink vulnerability.
CVE-2014-3421 affects GNU Emacs versions up to and including 24.3.
Yes, CVE-2014-3421 can impact Mageia systems running vulnerable versions of GNU Emacs.
CVE-2014-3421 utilizes a symlink attack on the /tmp/gnus.face.ppm temporary file to exploit the vulnerability.