Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Emacs Movemail POP3 Remote Format String Vulnerability

The movemail utility of Emacs is reported prone to a remote format-string vulnerability. This issue arises because the application fails to sanitize user-supplied data before passing it as the format specifier to a formatted-printing function.

A remote attacker may leverage this issue to write to arbitrary process memory, facilitating code execution. Any code execution would take place with setgid mail privileges.







 

Privacy Statement
Copyright 2009, SecurityFocus