CVE Vulnerabilities

CVE-2010-0825

Published: Apr 05, 2010 | Modified: Aug 17, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
3.3 LOW
AV:L/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.

Affected Software

Name Vendor Start Version End Version
Emacs Gnu 22.1 (including) 22.1 (including)
Emacs Gnu 22.2 (including) 22.2 (including)
Emacs Gnu 22.3 (including) 22.3 (including)
Emacs Gnu 23.1 (including) 23.1 (including)
Emacs21 Ubuntu dapper *
Emacs21 Ubuntu hardy *
Emacs21 Ubuntu intrepid *
Emacs21 Ubuntu jaunty *
Emacs21 Ubuntu upstream *
Emacs22 Ubuntu hardy *
Emacs22 Ubuntu intrepid *
Emacs22 Ubuntu jaunty *
Emacs22 Ubuntu karmic *
Emacs22 Ubuntu lucid *
Emacs22 Ubuntu maverick *
Emacs22 Ubuntu upstream *
Emacs23 Ubuntu devel *
Emacs23 Ubuntu karmic *
Emacs23 Ubuntu lucid *
Emacs23 Ubuntu maverick *
Emacs23 Ubuntu natty *
Emacs23 Ubuntu oneiric *
Emacs23 Ubuntu precise *
Emacs23 Ubuntu quantal *
Emacs23 Ubuntu raring *
Emacs23 Ubuntu saucy *
Emacs23 Ubuntu upstream *
Xemacs21 Ubuntu dapper *
Xemacs21 Ubuntu hardy *
Xemacs21 Ubuntu intrepid *
Xemacs21 Ubuntu jaunty *
Xemacs21 Ubuntu karmic *
Xemacs21 Ubuntu lucid *
Xemacs21 Ubuntu upstream *

References