CVE-2008-1694
Ubuntu Security Notice 607-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
vcdiff in Emacs 20.7 to 22.1.50, when used with SCCS, allows local users to overwrite arbitrary files via a symlink attack on temporary files.
vcdiff en Emacs 20.7 a 22.1.50, cuando es utilizado con SCCS, permite a usuarios locales sobrescribir ficheros de su elección a través de un ataque symlink en ficheros temporales.
It was discovered that Emacs did not account for precision when formatting integers. If a user were tricked into opening a specially crafted file, an attacker could cause a denial of service or possibly other unspecified actions. This issue does not affect Ubuntu 8.04. Steve Grubb discovered that the vcdiff script as included in Emacs created temporary files in an insecure way when used with SCCS. Local users could exploit a race condition to create or overwrite files with the privileges of the user invoking the program.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-04-08 CVE Reserved
- 2008-04-21 CVE Published
- 2024-08-07 CVE Updated
- 2025-07-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://bugs.gentoo.org/show_bug.cgi?id=216880 | X_refsource_confirm | |
http://secunia.com/advisories/29905 | Third Party Advisory | |
http://secunia.com/advisories/29926 | Third Party Advisory | |
http://secunia.com/advisories/30109 | Third Party Advisory | |
http://www.securityfocus.com/bid/28857 | Vdb Entry | |
http://www.securitytracker.com/id?1019909 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1309/references | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1310/references | Vdb Entry | |
https://bugzilla.redhat.com/show_bug.cgi?id=208483 | X_refsource_confirm | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41906 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.mandriva.com/security/advisories?name=MDVSA-2008:096 | 2018-10-03 | |
https://usn.ubuntu.com/607-1 | 2018-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | 20.7 Search vendor "Gnu" for product "Emacs" and version "20.7" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | 21.1 Search vendor "Gnu" for product "Emacs" and version "21.1" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | 21.2 Search vendor "Gnu" for product "Emacs" and version "21.2" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | 21.3 Search vendor "Gnu" for product "Emacs" and version "21.3" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Emacs Search vendor "Gnu" for product "Emacs" | 21.4 Search vendor "Gnu" for product "Emacs" and version "21.4" | - |
Affected
| ||||||
Gnu Search vendor "Gnu" | Sccs Search vendor "Gnu" for product "Sccs" | * | - |
Affected
|