CVE-2017-1000383 describes a vulnerability in GNU Emacs versions, including 25.3.1, where backup save files (e.g., "[ORIGINAL_FILENAME]~") are created without respecting the user's umask settings. This can lead to sensitive information disclosure as these files may become world-readable or otherwise accessible beyond the user's intent. The vulnerability has a CVSSv3 score of 5.5 (Medium), indicating a low attack complexity and local privileges required, with a high impact on confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 25.3.0CPE matchmatch criteria | cpe:2.3:a:gnu:emacs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.