First published: Sun Dec 28 2014(Updated: )
It was reported that a left-click in Emacs sometimes modifies the PRIMARY selection. Due to this bug, a paste with a middle click in a web browser can end up in pasting private data. This flaw affects Emacs version 24.4 only. Original report (also contains a reproducer): <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774090">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774090</a> CVE request and assignment: <a href="http://www.openwall.com/lists/oss-security/2015/01/03/15">http://www.openwall.com/lists/oss-security/2015/01/03/15</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/emacs24 | <=24.4+1-5<=24.4+1-4.1 | |
GNU Emacs | =24.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9483 is considered a moderate severity vulnerability due to the risk of unintended data exposure.
To fix CVE-2014-9483, update Emacs to a version later than 24.4, as this vulnerability affects only Emacs version 24.4.
CVE-2014-9483 affects only Emacs version 24.4.
CVE-2014-9483 may lead to the accidental pasting of private data when using a middle click in web browsers.
CVE-2014-9483 is generally not classified as a remote exploit, as it involves user interaction through Emacs.