|
Emacs Movemail POP3 Remote Format String Vulnerability
The movemail utility of Emacs is reported prone to a remote format-string vulnerability. This issue arises because the application fails to sanitize user-supplied data before passing it as the format specifier to a formatted-printing function. A remote attacker may leverage this issue to write to arbitrary process memory, facilitating code execution. Any code execution would take place with setgid mail privileges. |
|
|
Privacy Statement |