CVE Database
/

CVE-2007-5795

Back to search

CVE-2007-5795

Published: Nov 2, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration.

VendorProductVersions

n/a

n/a

affected
n/a

References

FEDORA-2007-3056
vendor-advisory
x_refsource_FEDORA
27984
third-party-advisory
x_refsource_SECUNIA
27728
third-party-advisory
x_refsource_SECUNIA
ADV-2008-0924
vdb-entry
x_refsource_VUPEN
ADV-2007-3715
vdb-entry
x_refsource_VUPEN
42060
vdb-entry
x_refsource_OSVDB
USN-541-1
vendor-advisory
x_refsource_UBUNTU
29420
third-party-advisory
x_refsource_SECUNIA
APPLE-SA-2008-03-18
vendor-advisory
x_refsource_APPLE
MDVSA-2008:034
vendor-advisory
x_refsource_MANDRIVA
26327
vdb-entry
x_refsource_BID
GLSA-200712-03
vendor-advisory
x_refsource_GENTOO
27508
third-party-advisory
x_refsource_SECUNIA
27627
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now