Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xemacs21-packages | Jul 30, 2024 | May 12, 2008 |
| Gentoo Linux | — | Upgrade app-editors/emacs.Upgrade app-xemacs/edit-utils. | Oct 30, 2017 | May 12, 2008 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 9, 2008 |
| Suse | — | Upgrade emacsUpgrade suse-releaseUpgrade emacs-x11Upgrade emacs-elUpgrade xemacs-packages-elUpgrade xemacs-packages-infoUpgrade emacs-noxUpgrade emacs-infoUpgrade xemacs-packages | Feb 17, 2015 | May 12, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub