Lucene search

K
kasperskyKaspersky LabKLA10169
HistoryMay 08, 2014 - 12:00 a.m.

KLA10169 WLF vulnerability in Emacs

2014-05-0800:00:00
Kaspersky Lab
threats.kaspersky.com
24

CVSS2

3.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%

An unspecified vulnerability was found in GNU Emacs. By exploiting this vulnerability malicious users can overwrite arbitrary tmp files. This vulnerability can be exploited locally via a symlink attack.

Original advisories

Related products

GNU-Emacs

CVE list

CVE-2014-3424 warning

CVE-2014-3423 warning

CVE-2014-3422 warning

CVE-2014-3421 warning

Solution

Update to latest version

Impacts

  • WLF

Write Local Files. Exploitation of vulnerabilities with this impact can lead to writing into some inaccessible files. Files that can be read depends on concrete program errors.

Affected Products

  • GNU Emacs versions 24.3 and earlier

CVSS2

3.3

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:M/Au:N/C:N/I:P/A:P

AI Score

6.2

Confidence

Low

EPSS

0

Percentile

5.1%