>> GNU Emacs Local Variable Processing Security Bypass Vulnerability
Title : GNU Emacs Local Variable Processing Security Bypass Vulnerability VUPEN ID : VUPEN/ADV-2007-3715 CVE ID : CVE-2007-5795
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-11-05
Technical Description
A vulnerability has been identified in GNU Emacs, which could be exploited by attackers to bypass security restrictions. This issue is caused by an error in the "hack-local-variables" function that does not properly validate local variables read from a file, which could be exploited by attackers to execute arbitrary Emacs Lisp code by tricking a user into opening a malicious file using an application with the "enable-local-variables" option set to ":safe".