Computer Security
Emacs safe mode protection bypass
updated since 14.11.2007
SecurityVulns ID:8343
Threat Level:
Description:It's possible to bypass enable-local-variables safe mode.
Affected:EMACS : emacs 22.1
CVE:CVE-2007-5795 (The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration.)
Original documentdocumentUBUNTU, [USN-541-1] Emacs vulnerability (14.11.2007)

