CVE-2010-0825

NameCVE-2010-0825
Descriptionlib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium
Debian Bugs590301

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xemacs21 (PTS)stretch21.4.24-4fixed
buster21.4.24-8fixed
sid, bullseye21.4.24-9fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
emacs21source(unstable)(unfixed)low
emacs22source(unstable)(unfixed)low590301
emacs23source(unstable)23.2+1-1low
xemacs21source(unstable)21.4.22-3.1low

Notes

[lenny] - emacs21 <no-dsa> (Minor issue)
Only exploitable when configured as setgid mail, which isn't set by default
[lenny] - emacs22 <no-dsa> (Minor issue)
[lenny] - xemacs21 <no-dsa> (Minor issue)
[lenny] - xmacs21 <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems