CVE-2014-3423: Low severity Mageia Project Mageia vulnerability
Published May 8, 2014
·Updated
lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.
Affected Software
27 affected components
Mageia Project Mageia=3
Mageia Project Mageia=4
GNU Emacs<=24.3
GNU Emacs=20.0
GNU Emacs=20.1
GNU Emacs=20.2
GNU Emacs=20.3
GNU Emacs=20.4
GNU Emacs=20.5
GNU Emacs=20.6
GNU Emacs=20.7
GNU Emacs=21
GNU Emacs=21.1
GNU Emacs=21.2
GNU Emacs=21.2.1
GNU Emacs=21.3
GNU Emacs=21.3.1
GNU Emacs=21.4
GNU Emacs=22.1
GNU Emacs=22.2
GNU Emacs=22.3
GNU Emacs=23.1
GNU Emacs=23.2
GNU Emacs=23.3
GNU Emacs=23.4
GNU Emacs=24.1
GNU Emacs=24.2
Event History
May 8, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-3423?
CVE-2014-3423 has a medium severity level due to its potential for local file overwriting through a symlink attack.
2
How do I fix CVE-2014-3423?
To fix CVE-2014-3423, you should upgrade to a version of GNU Emacs later than 24.3 or apply the recommended patches.
3
Who is affected by CVE-2014-3423?
CVE-2014-3423 affects local users of GNU Emacs versions 24.3 and earlier as well as Mageia versions 3 and 4.
4
What type of vulnerability is CVE-2014-3423?
CVE-2014-3423 is a symlink vulnerability that allows unauthorized overwriting of files.
5
Can CVE-2014-3423 be exploited remotely?
No, CVE-2014-3423 cannot be exploited remotely; it requires local access to the system.