4.6
CVSSv2

CVE-2008-1694

Published: 22/04/2008 Updated: 03/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu emacs 21.3

gnu emacs 21.4

gnu sccs

gnu emacs 20.7

gnu emacs 21.1

gnu emacs 21.2

Vendor Advisories

Debian Bug report logs - #476611 CVE-2008-1694: vcdiff insecure temporary file Package: emacs22; Maintainer for emacs22 is Rob Browning <rlb@defaultvalueorg>; Source for emacs22 is src:emacs (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 17 Apr 2008 22:06:13 UTC Severity: importan ...
It was discovered that Emacs did not account for precision when formatting integers If a user were tricked into opening a specially crafted file, an attacker could cause a denial of service or possibly other unspecified actions This issue does not affect Ubuntu 804 (CVE-2007-6109) ...