Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 81098
Alias:
Product:
Component:
Status: RESOLVED
Resolution: DUPLICATE of bug 79686
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Marco Morales <soulse@gmail.com>
Add CC:
CC:
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 81098 depends on: Show dependency tree
Bug 81098 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2005-02-07 04:53 0000
===========================================================
Ubuntu Security Notice USN-76-1           February 07, 2005
emacs21 vulnerability
CAN-2005-0100
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)

The following packages are affected:

emacs21-bin-common

The problem can be corrected by upgrading the affected package to
version 21.3+1-5ubuntu4.2. In general, a standard system upgrade is
sufficient to effect the necessary changes.

Details follow:

Max Vozeler discovered a format string vulnerability in the "movemail"
utility of Emacs. By sending specially crafted packets, a malicious
POP3 server could cause a buffer overflow, which could have been
exploited to execute arbitrary code with the privileges of the user
and the "mail" group (since "movemail" is installed as "setgid mail").


Reproducible: Didn't try
Steps to Reproduce:

------- Comment #1 From Thierry Carrez (RETIRED) 2005-02-07 05:03:00 0000 -------
Thanks Marco for finding that it is now public.

*** This bug has been marked as a duplicate of 79686 ***

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug