Date: Mon, 12 May 2008 18:49:48 +0200 From: Robert Buchholz <rbu@...too.org> To: oss-security@...ts.openwall.com Cc: Nico Golde <oss-security+ml@...lde.de> Subject: Re: CVE request: Emacs 21 fast-lock-mode arbitrary lips code execution On Monday, 12. May 2008, Nico Golde wrote: > Hi, > > * Robert Buchholz <rbu@...too.org> [2008-05-10 15:01]: > > Emacs 21 and Xemacs will execute any lisp code present in a .flc file > > that accompanies the file the user opens. > > The same applies to emacs22. Our emacs maintainer said version 22 would warn you that lisp code from the file would be executed. Could you confirm otherwise? Robert Download attachment "signature.asc " of type "application/pgp-signature" (190 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.