_______________________________________________________________________
Package : emacs
Date : April 20, 2010
Affected: 2008.0, 2009.0, 2009.1, 2010.0, Corporate 4.0,
Enterprise Server 5.0
_______________________________________________________________________
Problem Description:
A vulnerability has been found and corrected in emacs:
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to
read, modify, or delete arbitrary mailbox files via a symlink attack,
related to improper file-permission checks (CVE-2010-0825).
Packages for 2008.0 and 2009.0 are provided due to the Extended
Maintenance Program for those products.
The updated packages have been patched to correct this issue.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2010-0825
_______________________________________________________________________