First published: Tue Oct 31 2017(Updated: )
GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Emacs | <=25.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000383 is considered a medium severity vulnerability due to the potential exposure of sensitive data.
Updating GNU Emacs to version 25.3.1 or later will resolve the issue as it addresses the umask ignoring behavior.
GNU Emacs versions prior to 25.3.1, including version 25.3.0, are affected by CVE-2017-1000383.
CVE-2017-1000383 impacts the backup save files created by GNU Emacs, which may become world-readable.
Yes, CVE-2017-1000383 can lead to unintended data exposure, allowing unauthorized access to backup save files.