2.1
CVSSv2

CVE-2004-0422

Published: 07/07/2004 Updated: 11/07/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

flim prior to 1.14.3 creates temporary files insecurely, which allows local users to overwrite arbitrary files of the Emacs user via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu flim

Vendor Advisories

Synopsis semi security update Type/Severity Security Advisory: Low Topic Updated semi packages that fix vulnerabilities in flim temporary filehandling are now available Description The semi package includes a MIME library for GNU Emacs and XEmacs used bythe wl mail packageTatsuya Kinoshit ...
Tatsuya Kinoshita discovered a vulnerability in flim, an emacs library for working with internet messages, where temporary files were created without taking appropriate precautions This vulnerability could potentially be exploited by a local user to overwrite files with the privileges of the user running emacs For the current stable distribution ...