CVE-2010-0825
published 2010-04-05CVE-2010-0825: lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to…
PriorityP415medium4.4CVSS 2.0
AVLACMAuNCPIPAP
EPSS
0.33%
24.8th percentile
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | xemacs21 | < xemacs21 21.4.22-3.1 (bookworm) | xemacs21 21.4.22-3.1 (bookworm) |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4LOW
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNU emacs 22.1/22.2/22.3/23.1 Permission Check access control (Nessus ID 45588 / ID 195074)
vuldb·2026-05-05·CVSS 4.4
CVE-2010-0825 [MEDIUM] GNU emacs 22.1/22.2/22.3/23.1 Permission Check access control (Nessus ID 45588 / ID 195074)
A vulnerability was found in GNU emacs 22.1/22.2/22.3/23.1 and classified as problematic. Impacted is an unknown function of the component Permission Check. Such manipulation leads to improper access controls.
This vulnerability is traded as CVE-2010-0825. An attack has to be approached locally. There is no exploit available.
GHSA
GHSA-9x8g-36jg-fvcv: lib-src/movemail
ghsa_unreviewed·2022-05-02
CVE-2010-0825 [MEDIUM] GHSA-9x8g-36jg-fvcv: lib-src/movemail
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
OSV
CVE-2010-0825: lib-src/movemail
osv·2010-04-05·CVSS 4.4
CVE-2010-0825 [MEDIUM] CVE-2010-0825: lib-src/movemail
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
Red Hat
MySQL: Mysqld DoS (crash) by processing joins involving a table with a unique SET column (MySQL BZ#54575)
vendor_redhat·2010-07-09·CVSS 4.0
CVE-2010-3677 [MEDIUM] MySQL: Mysqld DoS (crash) by processing joins involving a table with a unique SET column (MySQL BZ#54575)
MySQL: Mysqld DoS (crash) by processing joins involving a table with a unique SET column (MySQL BZ#54575)
Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via a join query that uses a table with a unique SET column.
Statement: This issue did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 3 and 4. This issue was addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2010-0825.html.
Package: mysql (Red Hat Enterprise Linux 4) - Not affected
Red Hat
MySQL: mysqld DoS (crash) by processing EXPLAIN statements for complex SQL queries (MySQL bug #52711)
vendor_redhat·2010-07-09·CVSS 4.0
CVE-2010-3682 [MEDIUM] CWE-119 MySQL: mysqld DoS (crash) by processing EXPLAIN statements for complex SQL queries (MySQL bug #52711)
MySQL: mysqld DoS (crash) by processing EXPLAIN statements for complex SQL queries (MySQL bug #52711)
Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using EXPLAIN with crafted "SELECT ... UNION ... ORDER BY (SELECT ... WHERE ...)" statements, which triggers a NULL pointer dereference in the Item_singlerow_subselect::store function.
Statement: This issue did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 3 and 4. This issue was addressed in Red Hat Enterprise Linux 5 via https://rhn.redhat.com/errata/RHSA-2010-0825.html.
Package: mysql (Red Hat Enterprise Linux 4) - Not affected
Red Hat
MySQL: mysqld DoS (assertion failure) by alternate reads from two indexes on a table using the HANDLER interface (MySQL bug #54007)
vendor_redhat·2010-07-09·CVSS 4.0
CVE-2010-3681 [MEDIUM] MySQL: mysqld DoS (assertion failure) by alternate reads from two indexes on a table using the HANDLER interface (MySQL bug #54007)
MySQL: mysqld DoS (assertion failure) by alternate reads from two indexes on a table using the HANDLER interface (MySQL bug #54007)
Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by using the HANDLER interface and performing "alternate reads from two indexes on a table," which triggers an assertion failure.
Statement: This issue did not affect the versions of mysql as shipped with Red Hat Enterprise Linux 3. This issue was addressed in Red Hat Enterprise Linux 4, 5 and 6 via RHSA-2010:0824, RHSA-2010:0825 and RHSA-2011:0164 respectively.
Red Hat
xemacs: Race condition by moving message from user's inbox into user's Rmail file, when movemail setgid enabled
vendor_redhat·2010-03-29·CVSS 4.4
CVE-2010-0825 [MEDIUM] xemacs: Race condition by moving message from user's inbox into user's Rmail file, when movemail setgid enabled
xemacs: Race condition by moving message from user's inbox into user's Rmail file, when movemail setgid enabled
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
Statement: Not vulnerable. This issues does not affect the versions of emacs or xemacs as shipped with Red Hat Enterprise Linux. The movemail utility in Red Hat Enterprise Linux does not have the setgid bit set, which is required for this flaw to be exploitable.
Ubuntu
Emacs vulnerability
vendor_ubuntu·2010-03-29
CVE-2010-0825 Emacs vulnerability
Title: Emacs vulnerability
Summary: Emacs vulnerability
Dan Rosenberg discovered that the email helper in Emacs did not correctly
check file permissions. A local attacker could perform a symlink race
to read or append to another user's mailbox if it was stored under a
group-writable group-"mail" directory.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2010-0825: xemacs21 - lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, mo...
vendor_debian·2010·CVSS 4.4
CVE-2010-0825 [MEDIUM] CVE-2010-0825: xemacs21 - lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, mo...
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
Scope: local
bookworm: resolved (fixed in 21.4.22-3.1)
bullseye: resolved (fixed in 21.4.22-3.1)
sid: resolved (fixed in 21.4.22-3.1)
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/39155http://www.mandriva.com/security/advisories?name=MDVSA-2010:083http://www.ubuntu.com/usn/USN-919-1http://www.vupen.com/english/advisories/2010/0734http://www.vupen.com/english/advisories/2010/0952https://bugs.launchpad.net/ubuntu/+bug/531569https://exchange.xforce.ibmcloud.com/vulnerabilities/57457http://secunia.com/advisories/39155http://www.mandriva.com/security/advisories?name=MDVSA-2010:083http://www.ubuntu.com/usn/USN-919-1http://www.vupen.com/english/advisories/2010/0734http://www.vupen.com/english/advisories/2010/0952https://bugs.launchpad.net/ubuntu/+bug/531569https://exchange.xforce.ibmcloud.com/vulnerabilities/57457
2010-04-05
Published