vendor:
Emacs
by:
7.5
CVSS
HIGH
Arbitrary Command Execution
CWE
Product Name: Emacs
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Arbitrary Command Execution in Emacs with Local Variables
Attackers can modify a text file to include local variables containing shell commands in an 'eval' statement, leading to the execution of arbitrary commands.
Mitigation:
Ensure that user-supplied input is properly sanitized to prevent the execution of arbitrary commands.