CVE-2008-2142
published 2008-05-12CVE-2008-2142: Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.66%
88.4th percentile
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xemacs21-packages | < xemacs21-packages 2009.02.17-1 (bookworm) | xemacs21-packages 2009.02.17-1 (bookworm) |
| gnu | emacs | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6hwc-q43w-j73j: Emacs 21 and XEmacs automatically load and execute
ghsa_unreviewed·2022-05-01
CVE-2008-2142 [MEDIUM] GHSA-6hwc-q43w-j73j: Emacs 21 and XEmacs automatically load and execute
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.
OSV
CVE-2008-2142: Emacs 21 and XEmacs automatically load and execute
osv·2008-05-12·CVSS 6.8
CVE-2008-2142 [MEDIUM] CVE-2008-2142: Emacs 21 and XEmacs automatically load and execute
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.
Red Hat
emacs: fast-lock-mode arbitrary lisp code execution
vendor_redhat·2008-05-09·CVSS 6.8
CVE-2008-2142 [MEDIUM] CWE-829 emacs: fast-lock-mode arbitrary lisp code execution
emacs: fast-lock-mode arbitrary lisp code execution
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: emacs (Red Hat Enterprise Linux 4) - Will not fix
Package: xemacs (Red Hat Enterprise Linux 4) - Will not fix
Package: emacs (Red Hat Enterprise Linux 5) - Will not fix
Debian
CVE-2008-2142: xemacs21-packages - Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that a...
vendor_debian·2008·CVSS 6.8
CVE-2008-2142 [MEDIUM] CVE-2008-2142: xemacs21-packages - Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that a...
Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 2009.02.17-1)
bullseye: resolved (fixed in 2009.02.17-1)
sid: resolved (fixed in 2009.02.17-1)
No detection rules found.
No public exploits indexed.
http://lists.gnu.org/archive/html/emacs-devel/2008-05/msg00645.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.htmlhttp://secunia.com/advisories/30199http://secunia.com/advisories/30216http://secunia.com/advisories/30303http://secunia.com/advisories/30581http://secunia.com/advisories/30827http://secunia.com/advisories/34004http://security.gentoo.org/glsa/glsa-200902-06.xmlhttp://thread.gmane.org/gmane.emacs.devel/96903http://tracker.xemacs.org/XEmacs/its/issue378http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0177http://www.mandriva.com/security/advisories?name=MDVSA-2008:153http://www.mandriva.com/security/advisories?name=MDVSA-2008:154http://www.securityfocus.com/archive/1/492657/100/0/threadedhttp://www.securityfocus.com/bid/29176http://www.securitytracker.com/id?1020019http://www.vupen.com/english/advisories/2008/1539/referenceshttp://www.vupen.com/english/advisories/2008/1540/referenceshttps://bugs.gentoo.org/show_bug.cgi?id=221197https://exchange.xforce.ibmcloud.com/vulnerabilities/42362https://issues.rpath.com/browse/RPL-2529https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00736.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-June/msg00782.htmlhttp://lists.gnu.org/archive/html/emacs-devel/2008-05/msg00645.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.htmlhttp://secunia.com/advisories/30199http://secunia.com/advisories/30216http://secunia.com/advisories/30303http://secunia.com/advisories/30581http://secunia.com/advisories/30827http://secunia.com/advisories/34004http://security.gentoo.org/glsa/glsa-200902-06.xmlhttp://thread.gmane.org/gmane.emacs.devel/96903http://tracker.xemacs.org/XEmacs/its/issue378http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0177http://www.mandriva.com/security/advisories?name=MDVSA-2008:153http://www.mandriva.com/security/advisories?name=MDVSA-2008:154http://www.securityfocus.com/archive/1/492657/100/0/threadedhttp://www.securityfocus.com/bid/29176http://www.securitytracker.com/id?1020019http://www.vupen.com/english/advisories/2008/1539/referenceshttp://www.vupen.com/english/advisories/2008/1540/referenceshttps://bugs.gentoo.org/show_bug.cgi?id=221197https://exchange.xforce.ibmcloud.com/vulnerabilities/42362https://issues.rpath.com/browse/RPL-2529https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00736.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-June/msg00782.html
2008-05-12
Published