CVE Vulnerabilities

CVE-2010-0825

Published: Apr 05, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
3.3 LOW
AV:L/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.

Affected Software

NameVendorStart VersionEnd Version
EmacsGnu22.1 (including)22.1 (including)
EmacsGnu22.2 (including)22.2 (including)
EmacsGnu22.3 (including)22.3 (including)
EmacsGnu23.1 (including)23.1 (including)
Emacs21Ubuntudapper*
Emacs21Ubuntuhardy*
Emacs21Ubuntuintrepid*
Emacs21Ubuntujaunty*
Emacs21Ubuntuupstream*
Emacs22Ubuntuhardy*
Emacs22Ubuntuintrepid*
Emacs22Ubuntujaunty*
Emacs22Ubuntukarmic*
Emacs22Ubuntulucid*
Emacs22Ubuntumaverick*
Emacs22Ubuntuupstream*
Emacs23Ubuntudevel*
Emacs23Ubuntukarmic*
Emacs23Ubuntulucid*
Emacs23Ubuntumaverick*
Emacs23Ubuntunatty*
Emacs23Ubuntuoneiric*
Emacs23Ubuntuprecise*
Emacs23Ubuntuquantal*
Emacs23Ubunturaring*
Emacs23Ubuntusaucy*
Emacs23Ubuntuupstream*
Xemacs21Ubuntudapper*
Xemacs21Ubuntuhardy*
Xemacs21Ubuntuintrepid*
Xemacs21Ubuntujaunty*
Xemacs21Ubuntukarmic*
Xemacs21Ubuntulucid*
Xemacs21Ubuntuupstream*

References