MDVSA-2008:034 -- Mandriva emacsID: oval:org.secpod.oval:def:301377 | Date: (C)2012-01-07 (M)2021-06-02 |
Class: PATCH | Family: unix |
The hack-local-variable function in Emacs 22 prior to version 22.2, when enable-local-variables is set to ":safe", did not properly search lists of unsafe or risky variables, which could allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration . A stack-based buffer overflow in emacs could allow user-assisted attackers to cause an application crash or possibly have other unspecified impacts via a large precision value in an integer format string specifier to the format function . The updated packages have been patched to correct these issues.
Platform: |
Mandriva Linux 2007.0 |
Mandriva Linux 2007.1 |
Mandriva Linux 2008.0 |