Информационная безопасность
[RU] switch to
English Version



CVECVE-2007-5795
СтатусCandidate
ОписаниеThe hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration.
PhaseAssigned (02.11.2007)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5795
ReferencesBID : 26327
 CONFIRM : http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=4...
 XF : emacs-hacklocalvariables-security-bypass(38263)
SecurityVulns:Обход защиты в safe mode в Emacs

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server