unofficial mirror of bug-gnu-emacs@gnu.org 
 help / color / mirror / code / Atom feed
* bug#29182: CVE-2017-1000383: umask and backup files
@ 2017-11-06 21:56 Glenn Morris
  2017-11-07  1:57 ` Glenn Morris
  2019-10-06  4:08 ` Stefan Kangas
  0 siblings, 2 replies; 10+ messages in thread
From: Glenn Morris @ 2017-11-06 21:56 UTC (permalink / raw)
  To: 29182

Package: emacs
Version: 25.3
Tags: security

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000383

  GNU Emacs version 25.3.1 (and other versions most likely) ignores umask
  when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in
  files that may be world readable or otherwise accessible in ways not
  intended by the user running the emacs binary.

[I'm not sure why this apparently hasn't been reported here before now?]





^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2020-08-10 16:25 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2017-11-06 21:56 bug#29182: CVE-2017-1000383: umask and backup files Glenn Morris
2017-11-07  1:57 ` Glenn Morris
2017-11-07 19:29   ` Glenn Morris
2017-11-13 22:04     ` Glenn Morris
2017-11-14 15:24       ` Eli Zaretskii
2019-10-06  4:08 ` Stefan Kangas
2019-10-06 13:17   ` Noam Postavsky
2019-10-08  6:05   ` Glenn Morris
2019-10-08  9:24     ` Stefan Kangas
2020-08-10 16:25   ` Stefan Kangas

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/emacs.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).