CVE Vulnerabilities

CVE-2012-3479

Published: Aug 25, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
5.1 LOW
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file.

Affected Software

NameVendorStart VersionEnd Version
EmacsGnu23.2 (including)23.2 (including)
EmacsGnu23.3 (including)23.3 (including)
EmacsGnu23.4 (including)23.4 (including)
EmacsGnu24.1 (including)24.1 (including)
Emacs-snapshotUbuntuhardy*
Emacs-snapshotUbuntulucid*
Emacs-snapshotUbuntunatty*
Emacs21Ubuntuhardy*
Emacs22Ubuntuhardy*
Emacs23Ubuntudevel*
Emacs23Ubuntunatty*
Emacs23Ubuntuoneiric*
Emacs23Ubuntuprecise*
Emacs23Ubuntuquantal*
Emacs23Ubunturaring*
Emacs23Ubuntusaucy*
Emacs23Ubuntuupstream*
Emacs24Ubuntudevel*
Emacs24Ubuntuquantal*
Emacs24Ubunturaring*
Emacs24Ubuntusaucy*
Emacs24Ubuntuupstream*
Xemacs21Ubuntuhardy*

References