Description
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Affected products
- gnu / emacs20.7 – 20.7
- gnu / emacs21.1 – 21.1
- gnu / emacs21.2 – 21.2
- gnu / emacs21.3 – 21.3
- gnu / emacs21.4 – 21.4
- gnu / sccs
References
- VENDOR_ADVISORYhttps://usn.ubuntu.com/607-1/
- VENDOR_ADVISORYhttp://secunia.com/advisories/29905
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=208483
- VENDOR_ADVISORYhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:096
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2008/1309/references
- MISChttp://www.securitytracker.com/id?1019909
- VENDOR_ADVISORYhttp://secunia.com/advisories/29926
- VENDOR_ADVISORYhttp://secunia.com/advisories/30109
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/41906
- MISChttp://www.securityfocus.com/bid/28857
- MISChttp://bugs.gentoo.org/show_bug.cgi?id=216880
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2008/1310/references