lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file.
CVSS Details
- CVSS 3.1 Base Score: 6.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade emacs | Aug 30, 2017 | Aug 25, 2012 |
| Freebsd | — | Upgrade emacs | Dec 10, 2025 | Sep 8, 2012 |
| Gentoo Linux | — | Upgrade app-editors/emacs. | Oct 30, 2017 | Aug 25, 2012 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.2.0.0.42.0 on Solaris 11.2 | May 29, 2017 | Aug 25, 2012 |
| Suse | — | Upgrade skkdic-extraUpgrade emacs-elUpgrade emacs-w3Upgrade emacs-x11Upgrade emacs-noxUpgrade emacsUpgrade emacs-infoUpgrade skkdicUpgrade ddskkUpgrade gnuplotUpgrade gnuplot-doc | Dec 12, 2013 | Aug 25, 2012 |
| Ubuntu | — | Upgrade emacs23Upgrade emacs23-common | Nov 8, 2024 | Aug 25, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub