CVE-2012-3479
Publication date 25 August 2012
Last updated 24 July 2024
Ubuntu priority
lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file.
Status
Package | Ubuntu Release | Status |
---|---|---|
emacs-snapshot | ||
emacs21 | ||
emacs22 | ||
emacs23 | ||
emacs24 | ||
xemacs21 | ||
Notes
Patch details
Package | Patch details |
---|---|
emacs23 | |
emacs24 |
References
Related Ubuntu Security Notices (USN)
- USN-1586-1
- Emacs vulnerabilities
- 27 September 2012