oss-sec mailing list archives
Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution
From: Nico Golde <oss-security+ml () ngolde de>
Date: Mon, 12 May 2008 19:24:29 +0200
Hi Robert, * Robert Buchholz <rbu () gentoo org> [2008-05-12 19:05]:
On Monday, 12. May 2008, Nico Golde wrote:* Robert Buchholz <rbu () gentoo org> [2008-05-10 15:01]:Emacs 21 and Xemacs will execute any lisp code present in a .flc file that accompanies the file the user opens.The same applies to emacs22.Our emacs maintainer said version 22 would warn you that lisp code from the file would be executed. Could you confirm otherwise?
At least not with the emacs22 installation I tried this with (22.2). As this is a rather old version, this may depend on the version used? Cheers Nico -- Nico Golde - http://www.ngolde.de - nion () jabber ccc de - GPG: 0x73647CFF For security reasons, all text in this mail is double-rot13 encrypted.
Attachment:
_bin
Description:
Current thread:
- CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution Robert Buchholz (May 10)
- Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution Nico Golde (May 12)
- Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution Robert Buchholz (May 12)
- Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution Nico Golde (May 12)
- Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution Robert Buchholz (May 13)
- Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution Nico Golde (May 14)
- Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution Sven Joachim (May 14)
- Re: Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution Nico Golde (May 14)
- Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution Sven Joachim (May 14)
- Re: Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution Tavis Ormandy (May 14)
- vim $TMPDIR directory stat (was: [oss-security] Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution) Nico Golde (May 14)
- Re: Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution Gustavo De Nardin (spuk) (May 14)
- Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution Robert Buchholz (May 12)
- Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution Nico Golde (May 12)