Description
Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file, which allows user-assisted attackers to execute arbitrary commands, as demonstrated using the mode-name variable.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Georgi Guninski · textlocallinux
https://www.exploit-db.com/exploits/26492
References (6)
Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/15375
Vendor Advisory vendor-advisory
x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2005:208
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/17496
Issue Tracking x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=286183
Patch x_refsource_misc
http://lists.grok.org.uk/pipermail/full-disclosure/2003-May/005089.html
Scores
EPSS
0.0666
EPSS Percentile
91.3%
Details
Status
published
Products (1)
gnu/emacs
21.2.1
Published
Dec 31, 2003
Tracked Since
Feb 18, 2026