VYPR
Unrated severityNVD Advisory· Published May 8, 2014· Updated May 6, 2026

CVE-2014-3422

CVE-2014-3422

Description

lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.

Affected products

27
  • GNU/Emacs25 versions
    cpe:2.3:a:gnu:emacs:*:*:*:*:*:*:*:*+ 24 more
    • cpe:2.3:a:gnu:emacs:*:*:*:*:*:*:*:*range: <=24.3
    • cpe:2.3:a:gnu:emacs:20.0:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:20.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:20.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:20.3:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:20.4:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:20.5:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:20.6:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:20.7:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:21:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:21.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:21.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:21.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:21.3:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:21.3.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:21.4:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:22.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:22.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:22.3:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:23.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:23.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:23.3:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:23.4:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:24.1:*:*:*:*:*:*:*
    • cpe:2.3:a:gnu:emacs:24.2:*:*:*:*:*:*:*
  • cpe:2.3:o:mageia_project:mageia:3:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:mageia_project:mageia:3:*:*:*:*:*:*:*
    • cpe:2.3:o:mageia_project:mageia:4:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.