VulnerabilityModified
CVE-2008-2142
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.
MEDIUM 6.8EPSS 3.66%
Does this matter?
Lower severity and a low EPSS score (3.66%). Track it; it rarely justifies an emergency change on its own.
Description
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 3.66% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- gnu/emacs · gnu/xemacs
- Source
- cve@mitre.org
References
- http://lists.gnu.org/archive/html/emacs-devel/2008-05/msg00645.html
- http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html
- http://secunia.com/advisories/30199
- http://secunia.com/advisories/30216
- http://secunia.com/advisories/30303
- http://secunia.com/advisories/30581
- http://secunia.com/advisories/30827
- http://secunia.com/advisories/34004
- http://security.gentoo.org/glsa/glsa-200902-06.xml
- http://thread.gmane.org/gmane.emacs.devel/96903Exploit
- http://tracker.xemacs.org/XEmacs/its/issue378
- http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0177
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:153
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:154
- http://www.securityfocus.com/archive/1/492657/100/0/threaded
- http://www.securityfocus.com/bid/29176
- http://www.securitytracker.com/id?1020019
- http://www.vupen.com/english/advisories/2008/1539/references
- http://www.vupen.com/english/advisories/2008/1540/references
- https://bugs.gentoo.org/show_bug.cgi?id=221197
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42362
- https://issues.rpath.com/browse/RPL-2529
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00736.html
- https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00782.html
- http://lists.gnu.org/archive/html/emacs-devel/2008-05/msg00645.html
- http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html
- http://secunia.com/advisories/30199
- http://secunia.com/advisories/30216
- http://secunia.com/advisories/30303
- http://secunia.com/advisories/30581
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.