CVE-2014-9483
published 2017-08-28CVE-2014-9483: Emacs 24.4 allows remote attackers to bypass security restrictions.
PriorityP346high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
2.85%
85.1th percentile
Emacs 24.4 allows remote attackers to bypass security restrictions.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | emacs | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hh37-cm5v-2qrh: Emacs 24
ghsa_unreviewed·2022-05-17
CVE-2014-9483 [HIGH] CWE-200 GHSA-hh37-cm5v-2qrh: Emacs 24
Emacs 24.4 allows remote attackers to bypass security restrictions.
OSV
CVE-2014-9483: Emacs 24
osv·2017-08-28·CVSS 7.5
CVE-2014-9483 [HIGH] CVE-2014-9483: Emacs 24
Emacs 24.4 allows remote attackers to bypass security restrictions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9483 emacs: left-click modifies the PRIMARY selection
bugzilla·2015-01-13·CVSS 7.5
CVE-2014-9483 [HIGH] CVE-2014-9483 emacs: left-click modifies the PRIMARY selection
CVE-2014-9483 emacs: left-click modifies the PRIMARY selection
It was reported that a left-click in Emacs sometimes modifies the PRIMARY selection. Due to this bug, a paste with a middle click in a web browser can end up in pasting private data.
This flaw affects Emacs version 24.4 only.
Original report (also contains a reproducer):
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774090
CVE request and assignment:
http://www.openwall.com/lists/oss-security/2015/01/03/15
Discussion:
Created emacs tracking bugs for this issue:
Affects: fedora-all [bug 1181600]
---
Because of all versions rawhide, F22 and F21 have emacs-24.5 then I close the bug as CLOSED->CURRENTRELEASE.
Bugzilla
CVE-2014-9483 emacs: left-click modifies the PRIMARY selection [fedora-all]
bugzilla·2015-01-13·CVSS 7.5
CVE-2014-9483 [HIGH] CVE-2014-9483 emacs: left-click modifies the PRIMARY selection [fedora-all]
CVE-2014-9483 emacs: left-click modifies the PRIMARY selection [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fe
http://www.openwall.com/lists/oss-security/2015/01/03/15https://bugzilla.redhat.com/show_bug.cgi?id=1181599https://exchange.xforce.ibmcloud.com/vulnerabilities/99688http://www.openwall.com/lists/oss-security/2015/01/03/15https://bugzilla.redhat.com/show_bug.cgi?id=1181599https://exchange.xforce.ibmcloud.com/vulnerabilities/99688
2017-08-28
Published