Summary
Ubuntu Update for Linux kernel vulnerabilities USN-541-1
Solution
Please Install the Updated Packages.
Insight
Drake Wilson discovered that Emacs did not correctly handle the safe mode of "
enable-local-variables"
. If a user were tricked into opening
a specially crafted file while "
enable-local-variables"
was set to the
non-default "
:safe"
, a remote attacker could execute arbitrary commands with the user's privileges.
Affected
emacs22 vulnerability on Ubuntu 7.10
Severity
Classification
-
CVE CVE-2007-5795 -
CVSS Base Score: 6.3
AV:L/AC:M/Au:N/C:N/I:C/A:C
Related Vulnerabilities