CVE-2008-2142

critical

Description

Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.

References

https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00782.html

https://www.redhat.com/archives/fedora-package-announce/2008-June/msg00736.html

https://issues.rpath.com/browse/RPL-2529

https://exchange.xforce.ibmcloud.com/vulnerabilities/42362

https://euvd.enisa.europa.eu/vulnerability/EUVD-2008-2139

https://bugs.gentoo.org/show_bug.cgi?id=221197

http://www.vupen.com/english/advisories/2008/1540/references

http://www.vupen.com/english/advisories/2008/1539/references

http://www.securitytracker.com/id?1020019

http://www.securityfocus.com/bid/29176

http://www.securityfocus.com/archive/1/492657/100/0/threaded

http://www.mandriva.com/security/advisories?name=MDVSA-2008:154

http://www.mandriva.com/security/advisories?name=MDVSA-2008:153

http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0177

http://tracker.xemacs.org/XEmacs/its/issue378

http://thread.gmane.org/gmane.emacs.devel/96903

http://security.gentoo.org/glsa/glsa-200902-06.xml

http://secunia.com/advisories/34004

http://secunia.com/advisories/30827

http://secunia.com/advisories/30581

http://secunia.com/advisories/30303

http://secunia.com/advisories/30216

http://secunia.com/advisories/30199

http://lists.opensuse.org/opensuse-security-announce/2008-06/msg00001.html

http://lists.gnu.org/archive/html/emacs-devel/2008-05/msg00645.html

Details

Source: Mitre, NVD

Published: 2008-05-12

Updated: 2026-06-16

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.03826