LWN.net Logo

emacs: insecure temp files

Package(s):emacs21, emacs22 CVE #(s):CVE-2008-1694
Created:May 6, 2008 Updated:May 7, 2008
Description: From the Ubuntu advisory: Steve Grubb discovered that the vcdiff script as included in Emacs created temporary files in an insecure way when used with SCCS. Local users could exploit a race condition to create or overwrite files with the privileges of the user invoking the program.
Alerts:
Ubuntu USN-607-1 2008-05-06
Mandriva MDVSA-2008:096 2007-05-06

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.