CVE-2005-0100
published 2005-02-07CVE-2005-0100: Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote…
PriorityP434high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.36%
90.2th percentile
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xemacs21 | < xemacs21 21.4.16-2 (bookworm) | xemacs21 21.4.16-2 (bookworm) |
| gnu | emacs | <= 20.0 | — |
| gnu | emacs | — | — |
| gnu | xemacs | <= 21.4 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-39qf-gxpw-7vqf: Format string vulnerability in the movemail utility in (1) Emacs 20
ghsa_unreviewed·2022-05-01
CVE-2005-0100 [HIGH] GHSA-39qf-gxpw-7vqf: Format string vulnerability in the movemail utility in (1) Emacs 20
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
OSV
CVE-2005-0100: Format string vulnerability in the movemail utility in (1) Emacs 20
osv·2005-02-07·CVSS 7.5
CVE-2005-0100 [HIGH] CVE-2005-0100: Format string vulnerability in the movemail utility in (1) Emacs 20
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
Ubuntu
Emacs vulnerability
vendor_ubuntu·2005-02-07
CVE-2005-0100 Emacs vulnerability
Title: Emacs vulnerability
Summary: Emacs vulnerability
Max Vozeler discovered a format string vulnerability in the "movemail"
utility of Emacs. By sending specially crafted packets, a malicious
POP3 server could cause a buffer overflow, which could have been
exploited to execute arbitrary code with the privileges of the user
and the "mail" group (since "movemail" is installed as "setgid mail").
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-02-06·CVSS 7.5
CVE-2005-0100 [HIGH] security flaw
security flaw
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
Debian
CVE-2005-0100: xemacs21 - Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and...
vendor_debian·2005·CVSS 7.5
CVE-2005-0100 [HIGH] CVE-2005-0100: xemacs21 - Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and...
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
Scope: local
bookworm: resolved (fixed in 21.4.16-2)
bullseye: resolved (fixed in 21.4.16-2)
sid: resolved (fixed in 21.4.16-2)
No detection rules found.
Bugzilla
CVE-2005-0100 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-2005-0100 [HIGH] CVE-2005-0100 security flaw
CVE-2005-0100 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
Bugzilla
CAN-2005-0100 xemacs string format issue
bugzilla·2005-02-10
[MEDIUM] CAN-2005-0100 xemacs string format issue
CAN-2005-0100 xemacs string format issue
Max Vozeler discovered several format string vulnerabilities in the
movemail utility of XEmacs. If a user connects to a malicious POP server, an
attacker can execute arbitrary code as the user running xemacs. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2005-0100 to this issue.
Info:
https://rhn.redhat.com/errata/RHSA-2005-134.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0100
------- Bug moved to this database by [email protected] 2005-03-30 18:31 -------
This bug previously known as bug 2423 at https://bugzilla.fedora.us/
https://bugzilla.fedora.us/show_bug.cgi?id=2423
Originally filed under the Fedora Legacy product and Package request component.
Unknown priority P2. Setting to defaul
http://marc.info/?l=bugtraq&m=110780416112719&w=2http://www.debian.org/security/2005/dsa-670http://www.debian.org/security/2005/dsa-671http://www.debian.org/security/2005/dsa-685http://www.mandriva.com/security/advisories?name=MDKSA-2005:038http://www.redhat.com/support/errata/RHSA-2005-110.htmlhttp://www.redhat.com/support/errata/RHSA-2005-112.htmlhttp://www.redhat.com/support/errata/RHSA-2005-133.htmlhttp://www.securityfocus.com/archive/1/433928/30/5010/threadedhttp://www.securityfocus.com/bid/12462https://exchange.xforce.ibmcloud.com/vulnerabilities/19246https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9408http://marc.info/?l=bugtraq&m=110780416112719&w=2http://www.debian.org/security/2005/dsa-670http://www.debian.org/security/2005/dsa-671http://www.debian.org/security/2005/dsa-685http://www.mandriva.com/security/advisories?name=MDKSA-2005:038http://www.redhat.com/support/errata/RHSA-2005-110.htmlhttp://www.redhat.com/support/errata/RHSA-2005-112.htmlhttp://www.redhat.com/support/errata/RHSA-2005-133.htmlhttp://www.securityfocus.com/archive/1/433928/30/5010/threadedhttp://www.securityfocus.com/bid/12462https://exchange.xforce.ibmcloud.com/vulnerabilities/19246https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9408
2005-02-07
Published