CVE-2012-0035

Publication date 19 January 2012

Last updated 24 July 2024


Ubuntu priority

Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.

Read the notes from the security team

Status

Package Ubuntu Release Status
cedet 13.10 saucy Not in release
13.04 raring Not in release
12.10 quantal Not in release
12.04 LTS precise Not in release
11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick Ignored end of life
10.04 LTS lucid Ignored end of life
8.04 LTS hardy Ignored end of life
emacs22 13.10 saucy Not in release
13.04 raring Not in release
12.10 quantal Not in release
12.04 LTS precise Not in release
11.10 oneiric Not in release
11.04 natty Not in release
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Ignored end of life
emacs23 13.10 saucy
Not affected
13.04 raring
Not affected
12.10 quantal
Not affected
12.04 LTS precise
Fixed 23.3+1-1ubuntu9.1
11.10 oneiric
Fixed 23.3+1-1ubuntu4.1
11.04 natty Ignored
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Not in release

Notes


sbeattie

cedet was merged into emacs in 23.2


mdeslaur

natty is too close to EoL to be worth difficult backport, ignoring

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
emacs23

References

Related Ubuntu Security Notices (USN)

    • USN-1586-1
    • Emacs vulnerabilities
    • 27 September 2012

Other references