CVE-2012-0035
published 2012-01-19CVE-2012-0035: Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges…
PriorityP340critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.72%
84.4th percentile
Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| eric_m_ludlam | cedet | <= 1.0 | — |
| eric_m_ludlam | cedet | — | — |
| gnu | emacs | <= 23.3 | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hw9p-49fv-hhp6: Untrusted search path vulnerability in EDE in CEDET before 1
ghsa_unreviewed·2022-05-04
CVE-2012-0035 [HIGH] GHSA-hw9p-49fv-hhp6: Untrusted search path vulnerability in EDE in CEDET before 1
Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.
Ubuntu
Emacs vulnerabilities
vendor_ubuntu·2012-09-27·CVSS 9.3
CVE-2012-0035 [CRITICAL] Emacs vulnerabilities
Title: Emacs vulnerabilities
Summary: Emacs could be made to run programs as your login if it opened a specially
crafted file.
Hiroshi Oota discovered that Emacs incorrectly handled search paths. If a
user were tricked into opening a file with Emacs, a local attacker could
execute arbitrary Lisp code with the privileges of the user invoking the
program. (CVE-2012-0035)
Paul Ling discovered that Emacs incorrectly handled certain eval forms in
local-variable sections. If a user were tricked into opening a specially
crafted file with Emacs, a remote attacker could execute arbitrary Lisp
code with the privileges of the user invoking the program. (CVE-2012-3479)
Instructions: After a standard system update you need to restart Emacs to make all the
necessary changes.
Red Hat
emacs: CEDET global-ede-mode file loading vulnerability
vendor_redhat·2012-01-09·CVSS 9.3
CVE-2012-0035 [CRITICAL] emacs: CEDET global-ede-mode file loading vulnerability
emacs: CEDET global-ede-mode file loading vulnerability
Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.
Statement: Not vulnerable. This issue did not affect the versions of emacs as shipped with Red Hat Enterprise Linux 4, 5 or 6 as they did not include support for CEDET.
Package: emacs (Red Hat Enterprise Linux 4) - Not affected
Package: emacs (Red Hat Enterprise Linux 5) - Not affected
Package: emacs (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0035 emacs: CEDET global-ede-mode file loading vulnerability [fedora-all]
bugzilla·2012-01-10·CVSS 9.3
CVE-2012-0035 [CRITICAL] CVE-2012-0035 emacs: CEDET global-ede-mode file loading vulnerability [fedora-all]
CVE-2012-0035 emacs: CEDET global-ede-mode file loading vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=s
Bugzilla
CVE-2012-0035 emacs: CEDET global-ede-mode file loading vulnerability
bugzilla·2012-01-10·CVSS 9.3
CVE-2012-0035 [CRITICAL] CVE-2012-0035 emacs: CEDET global-ede-mode file loading vulnerability
CVE-2012-0035 emacs: CEDET global-ede-mode file loading vulnerability
A flaw was found in EDE (part of CEDET, and included in emacs and xemacs in Fedora). Quoting the report from emacs-devel [1]:
Hiroshi Oota has found a security flaw in EDE (part of CEDET), a
development tool included in Emacs. EDE can store various information
about a project, such as how to build the project, in a file named
Project.ede in the project directory tree. When the minor mode
`global-ede-mode' is enabled, visiting a file causes Emacs to look for
Project.ede in the file's directory or one of its parent directories.
If Project.ede is present, Emacs automatically reads and evaluates the
first Lisp expression in it.
This design exposes EDE users to the danger of loading malicious code
from one file (Project.e
Bugzilla
CVE-2012-0035 emacs: CEDET global-ede-mode file loading vulnerability [fedora-all]
bugzilla·2012-01-10·CVSS 9.3
CVE-2012-0035 [CRITICAL] CVE-2012-0035 emacs: CEDET global-ede-mode file loading vulnerability [fedora-all]
CVE-2012-0035 emacs: CEDET global-ede-mode file loading vulnerability [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=s
http://lists.fedoraproject.org/pipermail/package-announce/2012-January/072285.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-January/072288.htmlhttp://lists.gnu.org/archive/html/emacs-devel/2012-01/msg00387.htmlhttp://openwall.com/lists/oss-security/2012/01/10/2http://openwall.com/lists/oss-security/2012/01/10/4http://secunia.com/advisories/47311http://secunia.com/advisories/47515http://secunia.com/advisories/50801http://sourceforge.net/mailarchive/message.php?msg_id=28649762http://sourceforge.net/mailarchive/message.php?msg_id=28657612http://www.mandriva.com/security/advisories?name=MDVSA-2013:076http://www.ubuntu.com/usn/USN-1586-1https://security.gentoo.org/glsa/201812-05http://lists.fedoraproject.org/pipermail/package-announce/2012-January/072285.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-January/072288.htmlhttp://lists.gnu.org/archive/html/emacs-devel/2012-01/msg00387.htmlhttp://openwall.com/lists/oss-security/2012/01/10/2http://openwall.com/lists/oss-security/2012/01/10/4http://secunia.com/advisories/47311http://secunia.com/advisories/47515http://secunia.com/advisories/50801http://sourceforge.net/mailarchive/message.php?msg_id=28649762http://sourceforge.net/mailarchive/message.php?msg_id=28657612http://www.mandriva.com/security/advisories?name=MDVSA-2013:076http://www.ubuntu.com/usn/USN-1586-1https://security.gentoo.org/glsa/201812-05
2012-01-19
Published