The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration.
CVSS Details
- CVSS 3.1 Base Score: 9.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Emacs | — | Apply OS X security update 2008-002 | Dec 16, 2011 | Nov 2, 2007 |
| Gentoo Linux | — | Upgrade app-editors/emacs. | Oct 30, 2017 | Nov 2, 2007 |
| Suse | — | Upgrade emacs-noxUpgrade emacs-elUpgrade emacs-elnUpgrade emacsUpgrade emacs-infoUpgrade etagsUpgrade emacs-x11 | Dec 12, 2013 | Jul 9, 2013 |
| Ubuntu | — | Upgrade emacs22 | Nov 8, 2024 | Nov 2, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub