Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Linux All distros and thier applications

Reply
 
Thread Tools Display Modes
  #1  
Old 02-05-2008, 08:15 AM
Mandriva's Avatar
Mandriva Mandriva is offline
Senior Member
 
Join Date: Oct 2006
Posts: 720
Mandriva- Advisories MDVSA-2008:034: Updated emacs packages fix vulnerabilities

Advisories MDVSA-2008:034: Updated emacs packages fix vulnerabilities
The hack-local-variable function in Emacs 22 prior to version 22.2,
when enable-local-variables is set to ':safe', did not properly search
lists of unsafe or risky variables, which could allow user-assisted
attackers to bypass intended restrictions and modify critical
program variables via a file containing a Local variables declaration
(CVE-2007-5795; only affects Mandriva Linux 2008.0).

A stack-based buffer overflow in emacs could allow user-assisted
attackers to cause an application crash or possibly have other
unspecified impacts via a large precision value in an integer format
string specifier to the format function (CVE-2007-6109).

The updated packages have been patched to correct these issues.
http://mandrivausers.org/index.php?showtopic=48634
http://mandrivausers.org/index.php?showtopic=48634
Tue, 05 Feb 2008 06:50:24 +0000
Reply With Quote
Posted


Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is On
    Forum Jump



    All times are GMT -5. The time now is 05:25 AM.


    Firefox 2