emacs
Page content
- Vulnerable: 22.1-2
- Unaffected: 22.1-3kalgan1
Steve Grubb discovered that vcdiff script as shipped with Emacs uses temporary files insecurely, which makes it possible for local attacker to conduct a symlink attack and make the victim overwrite arbitrary file.
- Bug Tracker URL: http://bugs.frugalware.org/task/3006