Executive Summary

Summary
TitleEDE: Privilege escalation
Informations
NameGLSA-201812-05First vendor Publication2018-12-06
VendorGentooLast vendor Modification2018-12-06
Severity (Vendor) N/ARevisionN/A

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Cvss Base Score9.3Attack RangeNetwork
Cvss Impact Score10Attack ComplexityMedium
Cvss Expoit Score8.6AuthenticationNone Required
Calculate full CVSS 2.0 Vectors scores

Detail

Synopsis

A vulnerability in EDE could result in privilege escalation.

Background

A package that simplifies the task of creating, building, and debugging large programs with Emacs. It provides some of the features of an IDE, or Integrated Development Environment, in Emacs.

Description

An untrusted search path vulnerability was discovered in EDE.

Impact

A local attacker could escalate his privileges via a specially crafted Lisp expression in a Project.ede file in the directory or a parent directory of an opened file.

Workaround

There is no known workaround at this time.

Resolution

All EDE users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-xemacs/ede-1.07"

References

[ 1 ] CVE-2012-0035 : https://nvd.nist.gov/vuln/detail/CVE-2012-0035

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website:

https://security.gentoo.org/glsa/201812-05

Original Source

Url : http://security.gentoo.org/glsa/glsa-201812-05.xml

CPE : Common Platform Enumeration

TypeDescriptionCount
Application10
Application24

OpenVAS Exploits

DateDescription
2012-10-03Name : Ubuntu Update for emacs23 USN-1586-1
File : nvt/gb_ubuntu_USN_1586_1.nasl
2012-08-24Name : Fedora Update for emacs FEDORA-2012-11872
File : nvt/gb_fedora_2012_11872_emacs_fc16.nasl
2012-04-02Name : Fedora Update for emacs FEDORA-2012-0494
File : nvt/gb_fedora_2012_0494_emacs_fc16.nasl
2012-01-25Name : Fedora Update for emacs FEDORA-2012-0462
File : nvt/gb_fedora_2012_0462_emacs_fc15.nasl

Open Source Vulnerability Database (OSVDB)

idDescription
78244CEDET EDE Component Project.ede File Loading Weakness Remote LISP Code Execution

Nessus® Vulnerability Scanner

DateDescription
2018-12-07Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201812-05.nasl - Type : ACT_GATHER_INFO
2014-03-21Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201403-05.nasl - Type : ACT_GATHER_INFO
2014-01-28Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201401-31.nasl - Type : ACT_GATHER_INFO
2013-04-20Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2013-076.nasl - Type : ACT_GATHER_INFO
2012-09-28Name : The remote Ubuntu host is missing one or more security-related patches.
File : ubuntu_USN-1586-1.nasl - Type : ACT_GATHER_INFO
2012-01-24Name : The remote Fedora host is missing a security update.
File : fedora_2012-0494.nasl - Type : ACT_GATHER_INFO
2012-01-24Name : The remote Fedora host is missing a security update.
File : fedora_2012-0462.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
DateInformations
2018-12-07 00:18:34
  • First insertion