Fedora has issued an advisory on May 21: https://lists.fedoraproject.org/pipermail/package-announce/2014-May/133825.html Patched packages uploaded for Mageia 3, Mageia 4, and Cauldron. Advisory: ======================== Updated emacs packages fix security vulnerabilities: Steve Kemp discovered multiple temporary file handling issues in Emacs. A local attacker could use these flaws to perform symbolic link attacks against users running Emacs (CVE-2014-3421, CVE-2014-3422, CVE-2014-3423, CVE-2014-3424). References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3421 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3422 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3423 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3424 https://lists.fedoraproject.org/pipermail/package-announce/2014-May/133825.html ======================== Updated packages in core/updates_testing: ======================== emacs-24.2-5.1.mga3 emacs-el-24.2-5.1.mga3 emacs-doc-24.2-5.1.mga3 emacs-leim-24.2-5.1.mga3 emacs-nox-24.2-5.1.mga3 emacs-common-24.2-5.1.mga3 emacs-24.3-4.1.mga4 emacs-el-24.3-4.1.mga4 emacs-doc-24.3-4.1.mga4 emacs-leim-24.3-4.1.mga4 emacs-nox-24.3-4.1.mga4 emacs-common-24.3-4.1.mga4 from SRPMS: emacs-24.2-5.1.mga3.src.rpm emacs-24.3-4.1.mga4.src.rpm Reproducible: Steps to Reproduce:
Whiteboard: (none) => MGA3TOO
URL: (none) => http://lwn.net/Vulnerabilities/600793/
Checked the patches were applied to the files mentioned in the original report (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=747100) with madb rpmdiff feature and all applied so just ensuring emacs updates/starts ok for each arch.
Whiteboard: MGA3TOO => MGA3TOO has_procedure
Testing complete mga4 32 & 64
Whiteboard: MGA3TOO has_procedure => MGA3TOO has_procedure mga4-32-ok mga4-64-ok
Testing complete mga3 32 & 64 Validating. Advisory uploaded. Could sysadmin please push to 3 & 4 updates Thanks
Keywords: (none) => validated_updateWhiteboard: MGA3TOO has_procedure mga4-32-ok mga4-64-ok => MGA3TOO has_procedure advisory mga3-32-ok mga3-64-ok mga4-32-ok mga4-64-okCC: (none) => sysadmin-bugs
Update pushed: http://advisories.mageia.org/MGASA-2014-0250.html
Status: NEW => RESOLVEDCC: (none) => tmbResolution: (none) => FIXED