Vulnerabilities > CVE-2003-1232 - Local Variable Arbitrary Command Execution vulnerability in GNU Emacs 21.2.1

047910
CVSS 5.1 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
high complexity
gnu
exploit available

Summary

Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable.

Vulnerable Configurations

Part Description Count
Application
Gnu
1

Exploit-Db

descriptionEmacs 2.1 Local Variable Arbitrary Command Execution Vulnerability. CVE-2003-1232. Local exploit for linux platform
idEDB-ID:26492
last seen2016-02-03
modified2002-12-31
published2002-12-31
reporterGeorgi Guninski
sourcehttps://www.exploit-db.com/download/26492/
titleEmacs 2.1 - Local Variable Arbitrary Command Execution Vulnerability