USN-919-1: Emacs vulnerability
29 March 2010
Emacs vulnerability
Releases
Packages
Details
Dan Rosenberg discovered that the email helper in Emacs did not correctly
check file permissions. A local attacker could perform a symlink race
to read or append to another user's mailbox if it was stored under a
group-writable group-"mail" directory.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.10
Ubuntu 9.04
Ubuntu 8.10
Ubuntu 8.04
In general, a standard system upgrade is sufficient to effect the
necessary changes.