5.1
CVSSv2

CVE-2003-1232

Published: 31/12/2003 Updated: 08/03/2011
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
VMScore: 515
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted malicious users to execute arbitrary commands, as demonstrated using the mode-name variable.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu emacs 21.2.1

Exploits

source: wwwsecurityfocuscom/bid/15375/info Emacs is susceptible to an arbitrary command execution vulnerability with local variables This issue is due to insufficient sanitization of user-supplied input By modifying a text file to include local variables containing containing shell commands in an 'eval' statement, attackers may cause a ...