vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
gnu emacs 21.3 |
||
gnu emacs 21.4 |
||
gnu sccs |
||
gnu emacs 20.7 |
||
gnu emacs 21.1 |
||
gnu emacs 21.2 |