SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2008-2142

Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.

MEDIUM 6.8EPSS 3.66%

Does this matter?

Lower severity and a low EPSS score (3.66%). Track it; it rarely justifies an emergency change on its own.

Description

Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
3.66% probability · 89th percentile
CISA KEV
Not listed
Affected
gnu/emacs · gnu/xemacs
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.