Untrusted search path vulnerability in EDE in CEDET before 1.0.1, as used in GNU Emacs before 23.4 and other products, allows local users to gain privileges via a crafted Lisp expression in a Project.ede file in the directory, or a parent directory, of an opened file.
| Software | From | Fixed in |
|---|---|---|
| gnu / emacs | 22.1 | 22.1.x |
| eric_m_ludlam / cedet | 1.0-beta1 | 1.0-beta1.x |
| gnu / emacs | 21.1 | 21.1.x |
| gnu / emacs | 21.3 | 21.3.x |
| eric_m_ludlam / cedet | 1.0-pre2 | 1.0-pre2.x |
| gnu / emacs | 20.1 | 20.1.x |
| eric_m_ludlam / cedet | 1.0-beta2 | 1.0-beta2.x |
| eric_m_ludlam / cedet | 1.0-pre3 | 1.0-pre3.x |
| gnu / emacs | 20.5 | 20.5.x |
| gnu / emacs | - | 23.3.x |
| gnu / emacs | 20.4 | 20.4.x |
| eric_m_ludlam / cedet | 1.0-pre6 | 1.0-pre6.x |
| gnu / emacs | 20.7 | 20.7.x |
| gnu / emacs | 20.6 | 20.6.x |
| gnu / emacs | 21.2 | 21.2.x |
| eric_m_ludlam / cedet | 1.0-beta3 | 1.0-beta3.x |
| eric_m_ludlam / cedet | 1.0-pre7 | 1.0-pre7.x |
| gnu / emacs | 23.1 | 23.1.x |
| gnu / emacs | 20.2 | 20.2.x |
| gnu / emacs | 21.3.1 | 21.3.1.x |
| gnu / emacs | 22.3 | 22.3.x |
| eric_m_ludlam / cedet | 1.0-pre4 | 1.0-pre4.x |
| gnu / emacs | 23.4 | 23.4.x |
| gnu / emacs | 21 | 21.x |
| gnu / emacs | 20.3 | 20.3.x |
| gnu / emacs | 21.4 | 21.4.x |
| gnu / emacs | 21.2.1 | 21.2.1.x |
| gnu / emacs | 22.2 | 22.2.x |
| eric_m_ludlam / cedet | - | 1.0.x |
| gnu / emacs | 23.2 | 23.2.x |
| gnu / emacs | 20.0 | 20.0.x |
| eric_m_ludlam / cedet | 1.0-pre1 | 1.0-pre1.x |