Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain "emacs -batch -eval" command line.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Emacs | — | Apply OS X security update 2008-002 | Dec 16, 2011 | Dec 7, 2007 |
| Debian | — | Upgrade xemacs21 | Jul 30, 2024 | Dec 7, 2007 |
| Gentoo Linux | — | Upgrade app-editors/emacs. | Oct 30, 2017 | Dec 7, 2007 |
| Suse | — | Upgrade xemacs-elUpgrade emacs-x11Upgrade emacsUpgrade xemacsUpgrade emacs-noxUpgrade xemacs-infoUpgrade emacs-infoUpgrade emacs-elUpgrade suse-release | Feb 17, 2015 | Dec 7, 2007 |
| Ubuntu | — | Upgrade emacs22-bin-commonUpgrade emacs21-bin-commonUpgrade emacs22Upgrade emacs21 | Nov 8, 2024 | Dec 7, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub