[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

MDVSA-2008:034 -- Mandriva emacs

ID: oval:org.secpod.oval:def:301377Date: (C)2012-01-07   (M)2021-06-02
Class: PATCHFamily: unix




The hack-local-variable function in Emacs 22 prior to version 22.2, when enable-local-variables is set to ":safe", did not properly search lists of unsafe or risky variables, which could allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration . A stack-based buffer overflow in emacs could allow user-assisted attackers to cause an application crash or possibly have other unspecified impacts via a large precision value in an integer format string specifier to the format function . The updated packages have been patched to correct these issues.

Platform:
Mandriva Linux 2007.0
Mandriva Linux 2007.1
Mandriva Linux 2008.0
Product:
emacs
Reference:
MDVSA-2008:034
CVE-2007-5795
CVE-2007-6109
CVE    2
CVE-2007-6109
CVE-2007-5795
CPE    3
cpe:/o:mandriva:linux:2007.1
cpe:/o:mandriva:linux:2008.0
cpe:/o:mandriva:linux:2007.0

© SecPod Technologies