CVE-2014-9483: Infoleak
Emacs 24.4 allows remote attackers to bypass security restrictions.
Other sources
It was reported that a left-click in Emacs sometimes modifies the PRIMARY selection. Due to this bug, a paste with a middle click in a web browser can end up in pasting private data.
This flaw affects Emacs version 24.4 only.
Original report (also contains a reproducer):
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774090
CVE request and assignment:
http://www.openwall.com/lists/oss-security/2015/01/03/15
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9483?
CVE-2014-9483 is considered a moderate severity vulnerability due to the risk of unintended data exposure.
How do I fix CVE-2014-9483?
To fix CVE-2014-9483, update Emacs to a version later than 24.4, as this vulnerability affects only Emacs version 24.4.
Which versions of Emacs are affected by CVE-2014-9483?
CVE-2014-9483 affects only Emacs version 24.4.
What type of data is at risk due to CVE-2014-9483?
CVE-2014-9483 may lead to the accidental pasting of private data when using a middle click in web browsers.
Can CVE-2014-9483 be exploited remotely?
CVE-2014-9483 is generally not classified as a remote exploit, as it involves user interaction through Emacs.