CVE
- Id
- 1847
- CVE No.
- CVE-2000-0269
- Status
- Candidate
- Description
- Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.
- Phase
- Proposed (20000426)
- Votes
- ACCEPT(2) Baker, Levy | MODIFY(1) Frech | NOOP(3) Christey, Cole, Wall
- Comments
- Christey> ADDREF XF:emacs-local-eavesdrop | Verify BID for this - is it 1125, 1126, or 1127? | Also, ADDREF CALDERA:CSSA-2000-011.1 ?? | URL:ftp://ftp.calderasystems.com/pub/OpenLinux/security/CSSA-2000-011.1.txt | Frech> XF:emacs-local-eavesdrop | Christey> ADDREF MANDRAKE:MDKSA-2000:088 ? | Also http://www.securityfocus.com/bid/2164, but is that a | duplicate of BID:1125?