CVE-2007-5795

NameCVE-2007-5795
DescriptionThe hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDTSA-79-1
Debian Bugs449008

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
emacs22sourcelenny22.1+1-2+lenny1DTSA-79-1
emacs22source(unstable)22.1+1-2.1medium449008

Notes

Emacs 21 is not affected

Search for package or bug name: Reporting problems