lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "24.5+1-6ubuntu1", "binary_name": "emacs24" }, { "binary_version": "24.5+1-6ubuntu1", "binary_name": "emacs24-bin-common" }, { "binary_version": "24.5+1-6ubuntu1", "binary_name": "emacs24-bin-common-dbgsym" }, { "binary_version": "24.5+1-6ubuntu1", "binary_name": "emacs24-common" }, { "binary_version": "24.5+1-6ubuntu1", "binary_name": "emacs24-dbg" }, { "binary_version": "24.5+1-6ubuntu1", "binary_name": "emacs24-dbgsym" }, { "binary_version": "24.5+1-6ubuntu1", "binary_name": "emacs24-el" }, { "binary_version": "24.5+1-6ubuntu1", "binary_name": "emacs24-lucid" }, { "binary_version": "24.5+1-6ubuntu1", "binary_name": "emacs24-lucid-dbg" }, { "binary_version": "24.5+1-6ubuntu1", "binary_name": "emacs24-lucid-dbgsym" }, { "binary_version": "24.5+1-6ubuntu1", "binary_name": "emacs24-nox" }, { "binary_version": "24.5+1-6ubuntu1", "binary_name": "emacs24-nox-dbg" }, { "binary_version": "24.5+1-6ubuntu1", "binary_name": "emacs24-nox-dbgsym" } ] }