Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2012-3479

Publication date 25 August 2012

Last updated 24 July 2024


Ubuntu priority

lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file.

Read the notes from the security team

Status

Package Ubuntu Release Status
emacs-snapshot 13.10 saucy Not in release
13.04 raring Not in release
12.10 quantal Not in release
12.04 LTS precise Not in release
11.10 oneiric Not in release
11.04 natty Ignored
10.04 LTS lucid Ignored
8.04 LTS hardy Ignored
emacs21 13.10 saucy Not in release
13.04 raring Not in release
12.10 quantal Not in release
12.04 LTS precise Not in release
11.10 oneiric Not in release
11.04 natty Not in release
10.04 LTS lucid Not in release
8.04 LTS hardy Ignored
emacs22 13.10 saucy Not in release
13.04 raring Not in release
12.10 quantal Not in release
12.04 LTS precise Not in release
11.10 oneiric Not in release
11.04 natty Not in release
10.04 LTS lucid
Not affected
8.04 LTS hardy Ignored
emacs23 13.10 saucy
Fixed 23.4+1-4ubuntu1
13.04 raring
Fixed 23.4+1-4ubuntu1
12.10 quantal
Fixed 23.4+1-4ubuntu1
12.04 LTS precise
Fixed 23.3+1-1ubuntu9.1
11.10 oneiric
Fixed 23.3+1-1ubuntu4.1
11.04 natty Ignored
10.04 LTS lucid
Not affected
8.04 LTS hardy Not in release
emacs24 13.10 saucy
Fixed 24.1+1-2ubuntu3
13.04 raring
Fixed 24.1+1-2ubuntu3
12.10 quantal
Fixed 24.1+1-2ubuntu3
12.04 LTS precise Not in release
11.10 oneiric Not in release
11.04 natty Not in release
10.04 LTS lucid Not in release
8.04 LTS hardy Not in release
xemacs21 13.10 saucy
Not affected
13.04 raring
Not affected
12.10 quantal
Not affected
12.04 LTS precise
Not affected
11.10 oneiric
Not affected
11.04 natty
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Ignored

Notes


jdstrand

per upstream, 23.1 and earlier not affected


mdeslaur

natty is too close to EoL to be worth difficult backport, ignoring

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
emacs23
emacs24