CVE-2017-1000383 PUBLISHED

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.

EPSS 0.14% · 34.1th percentile

Risk Scores

EPSS Score
0.14%
34.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSemacs240, 24.5+1-1ubuntu2, 24.5+1-1ubuntu4
Ubuntu:Pro:18.04:LTSemacs250, 25.2+1-6, 25.2+1-6ubuntu0.1~esm2

Timeline

References

Open in Interactive Console →