OpenBSD VuXML: Documenting security issues in the OpenBSD Ports & Packages Collection

(X)emacs -- format string vulnerability

Affected packages
emacs < 21.3p1
Xemacs < 21.4.15p1

Details

VuXML ID 2b173998-7b9f-11d9-9d2e-080020f8e4df
Discovery 2005-02-08
Entry 2005-02-09

Max Vozeler discovered a format string vulnerability in the "movemail" utility of Emacs. By sending specially crafted packets, a malicious POP3 server could cause a buffer overflow, which could have been exploited to execute arbitrary code with the privileges of the user.

References

CVE Name CAN-2005-0100