CVE-2012-3479
published 2012-08-25CVE-2012-3479: lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to…
PriorityP433medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
3.79%
88.7th percentile
lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
| gnu | emacs | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_ubuntu9.3CRITICAL
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Emacs vulnerabilities
vendor_ubuntu·2012-09-27·CVSS 9.3
CVE-2012-0035 [CRITICAL] Emacs vulnerabilities
Title: Emacs vulnerabilities
Summary: Emacs could be made to run programs as your login if it opened a specially
crafted file.
Hiroshi Oota discovered that Emacs incorrectly handled search paths. If a
user were tricked into opening a file with Emacs, a local attacker could
execute arbitrary Lisp code with the privileges of the user invoking the
program. (CVE-2012-0035)
Paul Ling discovered that Emacs incorrectly handled certain eval forms in
local-variable sections. If a user were tricked into opening a specially
crafted file with Emacs, a remote attacker could execute arbitrary Lisp
code with the privileges of the user invoking the program. (CVE-2012-3479)
Instructions: After a standard system update you need to restart Emacs to make all the
necessary changes.
Red Hat
emacs: Evaluation of 'eval' forms in file-local variable sections, when 'enable-local-variables' set to ':safe'
vendor_redhat·2012-08-07·CVSS 6.8
CVE-2012-3479 [MEDIUM] emacs: Evaluation of 'eval' forms in file-local variable sections, when 'enable-local-variables' set to ':safe'
emacs: Evaluation of 'eval' forms in file-local variable sections, when 'enable-local-variables' set to ':safe'
lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file.
Statement: Not vulnerable. This issue did not affect the versions of emacs as shipped with Red Hat Enterprise Linux 5 and 6.
Package: emacs (Red Hat Enterprise Linux 5) - Not affected
Package: emacs (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-fh9m-xg7x-wmp2: lisp/files
ghsa_unreviewed·2022-05-17
CVE-2012-3479 [MEDIUM] GHSA-fh9m-xg7x-wmp2: lisp/files
lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file.
No detection rules found.
Bugzilla
CVE-2012-3479 emacs: Evaluation of 'eval' forms in file-local variable sections, when 'enable-local-variables' set to ':safe' [fedora-all]
bugzilla·2012-08-13·CVSS 6.8
CVE-2012-3479 [MEDIUM] CVE-2012-3479 emacs: Evaluation of 'eval' forms in file-local variable sections, when 'enable-local-variables' set to ':safe' [fedora-all]
CVE-2012-3479 emacs: Evaluation of 'eval' forms in file-local variable sections, when 'enable-local-variables' set to ':safe' [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission li
Bugzilla
CVE-2012-3479 emacs: Evaluation of 'eval' forms in file-local variable sections, when 'enable-local-variables' set to ':safe'
bugzilla·2012-08-13·CVSS 6.8
CVE-2012-3479 [MEDIUM] CVE-2012-3479 emacs: Evaluation of 'eval' forms in file-local variable sections, when 'enable-local-variables' set to ':safe'
CVE-2012-3479 emacs: Evaluation of 'eval' forms in file-local variable sections, when 'enable-local-variables' set to ':safe'
A security flaw was found in the file-variables code of emacs, a GNU Emacs text editor. When the Emacs user option 'enable-local-variables' was set to ':safe' (default is t), Emacs failed to refuse to evaluate 'eval' forms in file-local variable sections. A remote attacker could provide a specially-crafted file, that when processed by the Emacs Lisp plug-in would lead to arbitrary Lisp code execution with the privileges of the user running the Emacs editor, if the victim has had the 'enable-local-variables' option set to ':safe'.
Upstream bug:
[1] http://debbugs.gnu.org/cgi/bugreport.cgi?bug=12155
References:
[2] http://www.openwall.com/lists/oss-security/2012/08
http://debbugs.gnu.org/cgi/bugreport.cgi?bug=12155http://lists.opensuse.org/opensuse-updates/2012-10/msg00057.htmlhttp://secunia.com/advisories/50157http://secunia.com/advisories/50801http://www.debian.org/security/2013/dsa-2603http://www.mandriva.com/security/advisories?name=MDVSA-2013:076http://www.openwall.com/lists/oss-security/2012/08/13/1http://www.openwall.com/lists/oss-security/2012/08/13/2http://www.securityfocus.com/bid/54969http://www.securitytracker.com/id?1027375http://www.slackware.com/security/viewer.php?l=slackware-security&y=2012&m=slackware-security.420006http://www.ubuntu.com/usn/USN-1586-1http://debbugs.gnu.org/cgi/bugreport.cgi?bug=12155http://lists.opensuse.org/opensuse-updates/2012-10/msg00057.htmlhttp://secunia.com/advisories/50157http://secunia.com/advisories/50801http://www.debian.org/security/2013/dsa-2603http://www.mandriva.com/security/advisories?name=MDVSA-2013:076http://www.openwall.com/lists/oss-security/2012/08/13/1http://www.openwall.com/lists/oss-security/2012/08/13/2http://www.securityfocus.com/bid/54969http://www.securitytracker.com/id?1027375http://www.slackware.com/security/viewer.php?l=slackware-security&y=2012&m=slackware-security.420006http://www.ubuntu.com/usn/USN-1586-1
2012-08-25
Published