lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Emacs | Gnu | 22.1 (including) | 22.1 (including) |
Emacs | Gnu | 22.2 (including) | 22.2 (including) |
Emacs | Gnu | 22.3 (including) | 22.3 (including) |
Emacs | Gnu | 23.1 (including) | 23.1 (including) |
Emacs21 | Ubuntu | dapper | * |
Emacs21 | Ubuntu | hardy | * |
Emacs21 | Ubuntu | intrepid | * |
Emacs21 | Ubuntu | jaunty | * |
Emacs21 | Ubuntu | upstream | * |
Emacs22 | Ubuntu | hardy | * |
Emacs22 | Ubuntu | intrepid | * |
Emacs22 | Ubuntu | jaunty | * |
Emacs22 | Ubuntu | karmic | * |
Emacs22 | Ubuntu | lucid | * |
Emacs22 | Ubuntu | maverick | * |
Emacs22 | Ubuntu | upstream | * |
Emacs23 | Ubuntu | devel | * |
Emacs23 | Ubuntu | karmic | * |
Emacs23 | Ubuntu | lucid | * |
Emacs23 | Ubuntu | maverick | * |
Emacs23 | Ubuntu | natty | * |
Emacs23 | Ubuntu | oneiric | * |
Emacs23 | Ubuntu | precise | * |
Emacs23 | Ubuntu | quantal | * |
Emacs23 | Ubuntu | raring | * |
Emacs23 | Ubuntu | saucy | * |
Emacs23 | Ubuntu | upstream | * |
Xemacs21 | Ubuntu | dapper | * |
Xemacs21 | Ubuntu | hardy | * |
Xemacs21 | Ubuntu | intrepid | * |
Xemacs21 | Ubuntu | jaunty | * |
Xemacs21 | Ubuntu | karmic | * |
Xemacs21 | Ubuntu | lucid | * |
Xemacs21 | Ubuntu | upstream | * |