7.2
CVSSv2

CVE-2008-3949

Published: 22/09/2008 Updated: 08/08/2017
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

emacs/lisp/progmodes/python.el in Emacs 22.1 and 22.2 imports Python script from the current working directory during editing of a Python file, which allows local users to execute arbitrary code via a Trojan horse Python file.

Vulnerable Product Search on Vulmon Subscribe to Product

suse suse linux

Vendor Advisories

Debian Bug report logs - #499568 emacs22-common: CVE-2008-3949: Interactive Python Session loads module from current directory Package: emacs22-common; Maintainer for emacs22-common is (unknown); Reported by: Sven Joachim <svenjoac@gmxde> Date: Fri, 19 Sep 2008 22:36:01 UTC Severity: grave Tags: fixed-upstream, patch, sec ...