CVE-2007-5795

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/11/2007
Last modified:
09/04/2025

Description

The hack-local-variables function in Emacs before 22.2, when enable-local-variables is set to :safe, does not properly search lists of unsafe or risky variables, which might allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:debian:debian_linux:*:*:*:*:*:*:*:*
cpe:2.3:a:gnu:emacs:*:*:*:*:*:*:*:* 22.1 (including)
cpe:2.3:a:gnu:emacs:*:*:*:*:*:*:*:* 22.1 (including)


References to Advisories, Solutions, and Tools