Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000383

Опубликовано: 31 окт. 2017
Источник: debian

Описание

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.

Примечания

  • This CVE assignment is nonsense, GNU emacs reuses the umask of the original

  • file when creating a backup file. That's hardly incorrect behaviour

  • Upstream report: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=29182

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.

CVSS3: 5.5
redhat
больше 8 лет назад

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.

CVSS3: 5.5
nvd
больше 8 лет назад

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.

CVSS3: 5.5
github
больше 3 лет назад

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.