Lucene search

K
ubuntucveUbuntu.comUB:CVE-2017-1000383
HistoryOct 31, 2017 - 12:00 a.m.

CVE-2017-1000383

2017-10-3100:00:00
ubuntu.com
ubuntu.com
12

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

12.6%

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask
when creating a backup save file (“[ORIGINAL_FILENAME]~”) resulting in
files that may be world readable or otherwise accessible in ways not
intended by the user running the emacs binary.

Notes

Author Note
leosilva It really seems to not be a vulnerability. See all the comments around this issue in emacs. I’ll set it as ignored.

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

12.6%