6.3
CVSSv2

CVE-2007-5795

Published: 02/11/2007 Updated: 29/07/2017
CVSS v2 Base Score: 6.3 | Impact Score: 9.2 | Exploitability Score: 3.4
VMScore: 635
Vector: AV:L/AC:M/Au:N/C:N/I:C/A:C

Vulnerability Summary

The hack-local-variables function in Emacs prior to 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted malicious users to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu emacs

Vendor Advisories

Drake Wilson discovered that Emacs did not correctly handle the safe mode of “enable-local-variables” If a user were tricked into opening a specially crafted file while “enable-local-variables” was set to the non-default “:safe”, a remote attacker could execute arbitrary commands with the user’s privileges ...

Exploits

source: wwwsecurityfocuscom/bid/26327/info Emacs is prone to a vulnerability that lets attackers execute arbitrary code Due to a design error, the application ignores certain security settings and modifies local variables By supplying a malicious file, an attacker can exploit this issue to carry out various attacks, including executin ...