First published: Tue Jan 13 2015(Updated: )
It was reported that a left-click in Emacs sometimes modifies the PRIMARY selection. Due to this bug, a paste with a middle click in a web browser can end up in pasting private data. This flaw affects Emacs version 24.4 only. Original report (also contains a reproducer): <a href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774090">https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774090</a> CVE request and assignment: <a href="http://www.openwall.com/lists/oss-security/2015/01/03/15">http://www.openwall.com/lists/oss-security/2015/01/03/15</a>
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Emacs |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1181599 is categorized as a significant security vulnerability due to potential data leakage.
To fix REDHAT-BUG-1181599, update GNU Emacs to a version above 24.4 where this issue is resolved.
REDHAT-BUG-1181599 specifically affects Emacs version 24.4.
REDHAT-BUG-1181599 can lead to unintended modification of the PRIMARY selection during a left-click, causing private data to be pasted unexpectedly.
A temporary workaround for REDHAT-BUG-1181599 is to avoid using left-click actions in Emacs that could modify the PRIMARY selection until the issue is patched.