Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <A71BA2775357E5C6+acttvQU5RdxDk6tj@ut005408-PC>
Date: Tue, 31 Mar 2026 14:46:21 +0800
From: Tianyu Chen <sweetyfish@...pin.org>
To: oss-security@...ts.openwall.com
Cc: Christian Brabandt <cb@...bit.org>,
	Demi Marie Obenour <demiobenour@...il.com>
Subject: Re: [vim-security] Vim tabpanel modeline escape
 affects Vim < 9.2.0272

On Mon, Mar 30, 2026 at 06:20:28AM -0400, Demi Marie Obenour wrote:
> Should `modeline` be disabled by default in future releases?
> It's a huge attack surface.

In Debian, `modeline` is disabled by default.

https://salsa.debian.org/vim-team/vim/-/blob/debian/sid/debian/runtime/debian.vim#L10

Best,
Tianyu Chen @ deepin

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.