CVE-2007-6109
published 2007-12-07CVE-2007-6109: Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact…
PriorityP431critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.04%
86.0th percentile
Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain "emacs -batch -eval" command line.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xemacs21 | < xemacs21 21.4.21-4 (bookworm) | xemacs21 21.4.21-4 (bookworm) |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_msrc10.0CRITICAL
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
CVE-2007-6109: NIST NVD Details: https://nvd
vendor_msrc·2022-06-14·CVSS 10.0
CVE-2007-6109 [CRITICAL] CVE-2007-6109: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2007-6109
Mariner: Mariner
[email protected]: [email protected]
Customer Action Required: Yes
Exploit Status: DOS:N/A
Remediation: emacs
Ubuntu
Emacs vulnerabilities
vendor_ubuntu·2008-05-06·CVSS 10.0
CVE-2008-1694 [CRITICAL] Emacs vulnerabilities
Title: Emacs vulnerabilities
Summary: Emacs vulnerabilities
It was discovered that Emacs did not account for precision when formatting
integers. If a user were tricked into opening a specially crafted file, an
attacker could cause a denial of service or possibly other unspecified
actions. This issue does not affect Ubuntu 8.04. (CVE-2007-6109)
Steve Grubb discovered that the vcdiff script as included in Emacs created
temporary files in an insecure way when used with SCCS. Local users could
exploit a race condition to create or overwrite files with the privileges
of the user invoking the program. (CVE-2008-1694)
Instructions: After a standard system upgrade you need to restart Emacs to effect
the necessary changes.
Red Hat
Emacs buffer overflows
vendor_redhat·2007-12-07·CVSS 10.0
CVE-2007-6109 [CRITICAL] Emacs buffer overflows
Emacs buffer overflows
Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain "emacs -batch -eval" command line.
Statement: Red Hat does not consider this issue to be a security vulnerability since no trust boundary is crossed. The user must voluntarily interact with the attack mechanism to exploit this flaw, with the result being the ability to run code as themselves.
Debian
CVE-2007-6109: xemacs21 - Stack-based buffer overflow in emacs allows user-assisted attackers to cause a d...
vendor_debian·2007·CVSS 10.0
CVE-2007-6109 [CRITICAL] CVE-2007-6109: xemacs21 - Stack-based buffer overflow in emacs allows user-assisted attackers to cause a d...
Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain "emacs -batch -eval" command line.
Scope: local
bookworm: resolved (fixed in 21.4.21-4)
bullseye: resolved (fixed in 21.4.21-4)
sid: resolved (fixed in 21.4.21-4)
GHSA
GHSA-2gmr-48xr-j34m: Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified oth
ghsa_unreviewed·2022-05-01
CVE-2007-6109 [HIGH] CWE-119 GHSA-2gmr-48xr-j34m: Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified oth
Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain "emacs -batch -eval" command line.
OSV
CVE-2007-6109: Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified oth
osv·2007-12-07·CVSS 10.0
CVE-2007-6109 [CRITICAL] CVE-2007-6109: Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified oth
Stack-based buffer overflow in emacs allows user-assisted attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a large precision value in an integer format string specifier to the format function, as demonstrated via a certain "emacs -batch -eval" command line.
No detection rules found.
No public exploits indexed.
http://bugs.gentoo.org/show_bug.cgi?id=200297http://docs.info.apple.com/article.html?artnum=307562http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://secunia.com/advisories/27965http://secunia.com/advisories/27984http://secunia.com/advisories/28838http://secunia.com/advisories/29420http://secunia.com/advisories/30109http://security.gentoo.org/glsa/glsa-200712-03.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:034http://www.novell.com/linux/security/advisories/2007_25_sr.htmlhttp://www.vupen.com/english/advisories/2008/0924/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/38904https://usn.ubuntu.com/607-1/http://bugs.gentoo.org/show_bug.cgi?id=200297http://docs.info.apple.com/article.html?artnum=307562http://lists.apple.com/archives/security-announce/2008/Mar/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-02/msg00003.htmlhttp://secunia.com/advisories/27965http://secunia.com/advisories/27984http://secunia.com/advisories/28838http://secunia.com/advisories/29420http://secunia.com/advisories/30109http://security.gentoo.org/glsa/glsa-200712-03.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2008:034http://www.novell.com/linux/security/advisories/2007_25_sr.htmlhttp://www.vupen.com/english/advisories/2008/0924/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/38904https://usn.ubuntu.com/607-1/
2007-12-07
Published