HIGH
Emacs buffer overflows
Published Dec 7, 2007
10.0
HIGHCVSS 2.0
EPSS 3.04%
Description
Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain "emacs -batch -eval" command line.
Affected products
Remediation
Red Hat statement
Red Hat does not consider this issue to be a security vulnerability since no trust boundary is crossed. The user must voluntarily interact with the attack mechanism to exploit this flaw, with the result being the ability to run code as themselves.
Weaknesses (1)
References (20)
- http://bugs.gentoo.org/show_bug.cgi?id=200297 x_refsource_CONFIRM
- http://docs.info.apple.com/article.html?artnum=307562 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.html vendor-advisoryx_refsource_APPLE
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.html vendor-advisoryx_refsource_SUSE
- http://secunia.com/advisories/27965 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/27984 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/28838 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/29420 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/30109 third-party-advisoryx_refsource_SECUNIA
- http://security.gentoo.org/glsa/glsa-200712-03.xml vendor-advisoryx_refsource_GENTOO
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:034 vendor-advisoryx_refsource_MANDRIVA
- http://www.novell.com/linux/security/advisories/2007_25_sr.html vendor-advisoryx_refsource_SUSE
- http://www.vupen.com/english/advisories/2008/0924/references vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2007-6109 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=415751 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2007-6078 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38904 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2007-6109
- https://usn.ubuntu.com/607-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2007-6109
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 7, 2007
Updated Aug 7, 2024
Reserved Nov 23, 2007
Link CVE-2007-6109
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2007-6078 Assigner mitre
Published Dec 7, 2007
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2007-6078