CVE-2014-3422: Low severity GNU Emacs vulnerability
Published May 8, 2014
·Updated
lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.
Affected Software
27 affected components
GNU Emacs<=24.3
GNU Emacs=20.0
GNU Emacs=20.1
GNU Emacs=20.2
GNU Emacs=20.3
GNU Emacs=20.4
GNU Emacs=20.5
GNU Emacs=20.6
GNU Emacs=20.7
GNU Emacs=21
GNU Emacs=21.1
GNU Emacs=21.2
GNU Emacs=21.2.1
GNU Emacs=21.3
GNU Emacs=21.3.1
GNU Emacs=21.4
GNU Emacs=22.1
GNU Emacs=22.2
GNU Emacs=22.3
GNU Emacs=23.1
GNU Emacs=23.2
GNU Emacs=23.3
GNU Emacs=23.4
GNU Emacs=24.1
GNU Emacs=24.2
Mageia Project Mageia=3
Mageia Project Mageia=4
Event History
May 8, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3422?
CVE-2014-3422 has been classified as a medium severity vulnerability due to its potential for local file overwrite via symlink attacks.
2
How do I fix CVE-2014-3422?
To fix CVE-2014-3422, you should upgrade to GNU Emacs version 24.4 or later, which addresses this vulnerability.
3
Who is affected by CVE-2014-3422?
CVE-2014-3422 affects local users of GNU Emacs versions 24.3 and earlier, and select version 20.x to 23.x releases.
4
What kind of attack does CVE-2014-3422 involve?
CVE-2014-3422 involves a symlink attack that allows local users to overwrite arbitrary files.
5
When was CVE-2014-3422 discovered?
CVE-2014-3422 was discovered in May 2014.