Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000383

Опубликовано: 31 окт. 2017
Источник: redhat
CVSS3: 5.5

Описание

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.

It was found that emacs applies the opened file read permissions to the swap file, overriding the process' umask. An attacker might search for vim swap files, that were not deleted properly, in order to retrieve sensible data.

Отчет

This flaw is an incorrect permission assignment, where the application ignores the user's umask setting when creating a backup file (e.g., filename~).This behavior is triggered during normal file-saving operations. On a multi-user system, this could allow an unprivileged local user to read the contents of backup files created by other users. This results in a low-impact information disclosure of the file's previous contents, the practical impact is limited to these specific shared-environment scenarios and does not allow an attacker to modify data or execute code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5emacsWill not fix
Red Hat Enterprise Linux 6emacsWill not fix
Red Hat Enterprise Linux 7emacsWill not fix
Red Hat Enterprise Linux 9emacsAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=1508788emacs: Ignores umask when creating a swap file

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.

CVSS3: 5.5
nvd
почти 9 лет назад

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.

CVSS3: 5.5
debian
почти 9 лет назад

GNU Emacs version 25.3.1 (and other versions most likely) ignores umas ...

CVSS3: 5.5
github
больше 4 лет назад

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.

5.5 Medium

CVSS3