CVE-2008-1694
published 2008-04-22CVE-2008-1694: vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
PriorityP415medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.40%
31.9th percentile
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xemacs21 | < xemacs21 21.4.21-4 (bookworm) | xemacs21 21.4.21-4 (bookworm) |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_ubuntu10.0CRITICAL
vendor_debian4.6LOW
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Emacs vulnerabilities
vendor_ubuntu·2008-05-06·CVSS 10.0
CVE-2008-1694 [CRITICAL] Emacs vulnerabilities
Title: Emacs vulnerabilities
Summary: Emacs vulnerabilities
It was discovered that Emacs did not account for precision when formatting
integers. If a user were tricked into opening a specially crafted file, an
attacker could cause a denial of service or possibly other unspecified
actions. This issue does not affect Ubuntu 8.04. (CVE-2007-6109)
Steve Grubb discovered that the vcdiff script as included in Emacs created
temporary files in an insecure way when used with SCCS. Local users could
exploit a race condition to create or overwrite files with the privileges
of the user invoking the program. (CVE-2008-1694)
Instructions: After a standard system upgrade you need to restart Emacs to effect
the necessary changes.
Red Hat
emacs insecure /tmp file usage
vendor_redhat·2008-04-11·CVSS 4.6
CVE-2008-1694 [MEDIUM] CWE-377 emacs insecure /tmp file usage
emacs insecure /tmp file usage
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Package: emacs (Red Hat Enterprise Linux 4) - Will not fix
Package: emacs (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2008-1694: xemacs21 - vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to over...
vendor_debian·2008·CVSS 4.6
CVE-2008-1694 [MEDIUM] CVE-2008-1694: xemacs21 - vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to over...
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Scope: local
bookworm: resolved (fixed in 21.4.21-4)
bullseye: resolved (fixed in 21.4.21-4)
sid: resolved (fixed in 21.4.21-4)
GHSA
GHSA-7cqh-9wjj-hhf9: vcdiff in Emacs 20
ghsa_unreviewed·2022-05-01
CVE-2008-1694 [MEDIUM] CWE-59 GHSA-7cqh-9wjj-hhf9: vcdiff in Emacs 20
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
OSV
CVE-2008-1694: vcdiff in Emacs 20
osv·2008-04-22·CVSS 4.6
CVE-2008-1694 [MEDIUM] CVE-2008-1694: vcdiff in Emacs 20
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
No detection rules found.
No public exploits indexed.
http://bugs.gentoo.org/show_bug.cgi?id=216880http://secunia.com/advisories/29905http://secunia.com/advisories/29926http://secunia.com/advisories/30109http://www.mandriva.com/security/advisories?name=MDVSA-2008:096http://www.securityfocus.com/bid/28857http://www.securitytracker.com/id?1019909http://www.vupen.com/english/advisories/2008/1309/referenceshttp://www.vupen.com/english/advisories/2008/1310/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=208483https://exchange.xforce.ibmcloud.com/vulnerabilities/41906https://usn.ubuntu.com/607-1/http://bugs.gentoo.org/show_bug.cgi?id=216880http://secunia.com/advisories/29905http://secunia.com/advisories/29926http://secunia.com/advisories/30109http://www.mandriva.com/security/advisories?name=MDVSA-2008:096http://www.securityfocus.com/bid/28857http://www.securitytracker.com/id?1019909http://www.vupen.com/english/advisories/2008/1309/referenceshttp://www.vupen.com/english/advisories/2008/1310/referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=208483https://exchange.xforce.ibmcloud.com/vulnerabilities/41906https://usn.ubuntu.com/607-1/
2008-04-22
Published