| Vulnerability Name: | CVE-2008-1694 (CCN-41906) | ||||||||
| Assigned: | 2008-04-08 | ||||||||
| Published: | 2008-04-08 | ||||||||
| Updated: | 2018-10-03 | ||||||||
| Summary: | vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files. | ||||||||
| CVSS v3 Severity: | 5.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 4.0 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:OF/RC:C)
2.9 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-59 | ||||||||
| Vulnerability Consequences: | File Manipulation | ||||||||
| References: | Source: CONFIRM Type: UNKNOWN http://bugs.gentoo.org/show_bug.cgi?id=216880 Source: MITRE Type: CNA CVE-2008-1694 Source: CCN Type: GNU Web site Index of ftp.gnu.org/gnu/emacs Source: CCN Type: GNU Emacs CVS Repository emacs - CVS Repositories Source: CCN Type: SA29905 GNU Emacs vcdiff Insecure Temporary Files Source: SECUNIA Type: UNKNOWN 29905 Source: CCN Type: SA29926 XEmacs vcdiff Insecure Temporary Files Source: SECUNIA Type: UNKNOWN 29926 Source: SECUNIA Type: UNKNOWN 30109 Source: CCN Type: SECTRACK ID: 1019909 GNU Emacs vcdiff Unsafe Temporary File Lets Local Users Gain Elevated Privileges Source: MANDRIVA Type: UNKNOWN MDVSA-2008:096 Source: CCN Type: OSVDB ID: 44566 GNU Emacs vcdiff Symlink Arbitrary File Overwrite Source: BID Type: UNKNOWN 28857 Source: CCN Type: BID-28857 GNU Emacs Insecure Temporary File Creation Vulnerability Source: SECTRACK Type: UNKNOWN 1019909 Source: CCN Type: USN-607-1 Emacs vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2008-1309 Source: VUPEN Type: UNKNOWN ADV-2008-1310 Source: CCN Type: XEmacs Web site XEmacs: The next generation of Emacs Source: CCN Type: Red Hat Bugzilla Bug 208483 CVE-2008-1694 emacs insecure /tmp file usage Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=208483 Source: XF Type: UNKNOWN xemacs-gnuemacs-vcdiff-symlink(41906) Source: XF Type: UNKNOWN xemacs-gnuemacs-vcdiff-symlink(41906) Source: UBUNTU Type: UNKNOWN USN-607-1 | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| Oval Definitions | |||||||||
| |||||||||
| BACK | |||||||||