|
|
Message-ID: <A71BA2775357E5C6+acttvQU5RdxDk6tj@ut005408-PC> Date: Tue, 31 Mar 2026 14:46:21 +0800 From: Tianyu Chen <sweetyfish@...pin.org> To: oss-security@...ts.openwall.com Cc: Christian Brabandt <cb@...bit.org>, Demi Marie Obenour <demiobenour@...il.com> Subject: Re: [vim-security] Vim tabpanel modeline escape affects Vim < 9.2.0272 On Mon, Mar 30, 2026 at 06:20:28AM -0400, Demi Marie Obenour wrote: > Should `modeline` be disabled by default in future releases? > It's a huge attack surface. In Debian, `modeline` is disabled by default. https://salsa.debian.org/vim-team/vim/-/blob/debian/sid/debian/runtime/debian.vim#L10 Best, Tianyu Chen @ deepin
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.