Mandriva Linux Security Advisory – The hack-local-variable function in Emacs 22 prior to version 22.2, when enable-local-variables is set to ‘:safe’, did not properly search lists of unsafe or risky variables, which could allow user-assisted attackers to bypass intended restrictions and modify critical program variables via a file containing a Local variables declaration. A stack-based buffer overflow in emacs could allow user-assisted attackers to cause an application crash or possibly have other unspecified impacts via a large precision value in an integer format string specifier to the format function.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/63290/MDVSA-2008-034.txt
Source: https://packetstormsecurity.com/files/63290/Mandriva-Linux-Security-Advisory-2008-034.html

