Vulnerability CVE-2001-1301


Published: 2001-08-07   Modified: 2012-02-12

Description:
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.

CVSS2 => (AV:L/AC:H/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
1.2/10
2.9/10
1.9/10
Exploit range
Attack complexity
Authentication
Local
High
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Xemacs -> Xemacs 
GNU -> Emacs 

 References:
http://savannah.gnu.org/cgi-bin/viewcvs/emacs/emacs/lib-src/rcs2log?only_with_tag=EMACS_PRETEST_21_0_95
http://archives.neohapsis.com/archives/bugtraq/2001-08/0093.html
http://www.iss.net/security_center/static/11210.php

Copyright 2024, cxsecurity.com

 

Back to Top