« List of all CVEs

CVE-2007-5795

Published: 11/2/2007 Last updated: 8/7/2024 Reserved: 11/2/2007

The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (1)

conf-emacs

Products affected (1)

Product Vendor Version
n/a n/a SD730

References (38)