Vulnerability Name: | CVE-2017-1000383 (CCN-134467) | ||||||||||||||||||||||||||||
Assigned: | 2017-10-31 | ||||||||||||||||||||||||||||
Published: | 2017-10-31 | ||||||||||||||||||||||||||||
Updated: | 2017-11-27 | ||||||||||||||||||||||||||||
Summary: | GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) 4.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:U/RC:R)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-1000383 Source: CCN Type: oss-sec Mailing List, Tue, 31 Oct 2017 13:23:52 +0100 20171031 Fw: Security risk of vim swap files Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20171031 Fw: Security risk of vim swap files Source: BID Type: Third Party Advisory, VDB Entry 101671 Source: CCN Type: BID-101671 GNU Emacs CVE-2017-1000383 Local Information Disclosure Vulnerability Source: XF Type: UNKNOWN gnu-emacs-cve20171000383-info-disc(134467) Source: CCN Type: GNU Emacs Web site GNU Emacs - GNU Project Source: CCN Type: WhiteSource Vulnerability Database CVE-2017-1000383 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |