CVE-2014-3424: Low severity Mageia Project Mageia vulnerability
lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3424?
CVE-2014-3424 is considered a medium severity vulnerability due to its potential to allow local users to overwrite arbitrary files through a symlink attack.
How do I fix CVE-2014-3424?
To address CVE-2014-3424, you should upgrade to a version of GNU Emacs that is later than 24.3, as this vulnerability has been patched in subsequent releases.
Who is affected by CVE-2014-3424?
CVE-2014-3424 affects local users on GNU Emacs versions 24.3 and earlier, as well as certain versions of Mageia.
What causes CVE-2014-3424?
CVE-2014-3424 is caused by a flaw in the handling of temporary files in tramp-sh.el, which allows symlink attacks.
Is CVE-2014-3424 a remote vulnerability?
No, CVE-2014-3424 is not a remote vulnerability; it requires local access to exploit.