CVE-2007-5795 describes a vulnerability in GNU Emacs versions prior to 22.2, specifically within the hack-local-variables function. When the enable-local-variables setting was configured to :safe, the function failed to adequately search for unsafe or risky variables, potentially allowing user-assisted attackers to bypass security restrictions. This could lead to the modification of critical program variables through a malicious file containing a Local variables declaration. The vulnerability carries a CVSS score of 6.3, indicating a medium severity. It requires local access (AV:L) and medium attack complexity (AC:M), with no authentication needed (Au:N). The primary impact is on integrity (I:C) and availability (A:C), with no confidentiality impact (C:N). There is no evidence of active exploitation in the wild, and it is not listed in the KEV catalog. While no Metasploit or Nuclei modules exist, an exploit (EDB-30736) for code execution in Emacs 22.1 is available on ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 22.1CPE matchmatch criteria | cpe:2.3:a:gnu:emacs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:N/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.