Title : Slackware Security Update Fixes Emacs Movemail Buffer Overflow VUPEN ID : VUPEN/ADV-2005-1156 CVE ID : GENERIC-MAP-NOMATCH CWE ID : CWE-
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-07-21
Technical Description
Slackware has released updated packages to address a vulnerability identified in Emacs. This flaw is due to a buffer overflow error in the movemail utility that does not properly handle specially crafted POP3 replies, which could be exploited via a malicious POP3 server to execute arbitrary commands with the privileges of the user running emacs.