Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.51304
Category:Ubuntu Local Security Checks
Title:Ubuntu 4.10 USN-76-1 (emacs21)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to emacs21
announced via advisory USN-76-1.

Max Vozeler discovered a format string vulnerability in the 'movemail'
utility of Emacs. By sending specially crafted packets, a malicious
POP3 server could cause a buffer overflow, which could have been
exploited to execute arbitrary code with the privileges of the user
and the 'mail' group (since 'movemail' is installed as 'setgid mail').

The following packages are affected: emacs21-bin-common

Solution:
The problem can be corrected by upgrading the affected package to
version 21.3+1-5ubuntu4.2. In general, a standard system upgrade is
sufficient to effect the necessary changes.

http://lists.ubuntu.com/archives/ubuntu-security-announce/2005-February/000079.html

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-0100
BugTraq ID: 12462
http://www.securityfocus.com/bid/12462
Bugtraq: 20050207 [USN-76-1] Emacs vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=110780416112719&w=2
Debian Security Information: DSA-670 (Google Search)
http://www.debian.org/security/2005/dsa-670
Debian Security Information: DSA-671 (Google Search)
http://www.debian.org/security/2005/dsa-671
Debian Security Information: DSA-685 (Google Search)
http://www.debian.org/security/2005/dsa-685
http://www.securityfocus.com/archive/1/433928/30/5010/threaded
http://www.mandriva.com/security/advisories?name=MDKSA-2005:038
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9408
http://www.redhat.com/support/errata/RHSA-2005-110.html
http://www.redhat.com/support/errata/RHSA-2005-112.html
http://www.redhat.com/support/errata/RHSA-2005-133.html
XForce ISS Database: xemacs-movemail-format-string(19246)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19246
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.