[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
bug#28350: enriched.el code execution
From: |
Paul Eggert |
Subject: |
bug#28350: enriched.el code execution |
Date: |
Mon, 11 Sep 2017 09:38:14 -0700 |
User-agent: |
Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.3.0 |
On 09/11/2017 08:33 AM, Glenn Morris wrote:
I submitted this tohttps://github.com/distributedweaknessfiling/ .
I see you sent it tohttp://seclists.org/oss-sec/2017/q3/422 .
Yes, I sent it to the oss-security mailing list, and it is archived here:
http://www.openwall.com/lists/oss-security/2017/09/11/1
Are you sure this issue affects Emacs 19.29, as stated there?
The x-display code is "only" present since 21.1, AFAICS.
Thanks for checking. When I wrote that, I looked for any of the text
involved in Lars's patch. If a smaller patch will do, that might explain
why you're seeing 21.1 rather than 19.29. We can mention 21.1 instead of
19.29 in the 25.3 release, and I'll update etc/NEWS accordingly in
emacs-25 and master once that comes out.
These days almost nobody is running Emacs older than 21.1, so the exact
version number shouldn't matter to anybody other than software
archaeologists.
- bug#28350: enriched.el code execution, (continued)
- bug#28350: enriched.el code execution, Paul Eggert, 2017/09/09
- bug#28350: enriched.el code execution, Eli Zaretskii, 2017/09/11
- bug#28350: enriched.el code execution, Charles A. Roelli, 2017/09/11
- bug#28350: enriched.el code execution, Eli Zaretskii, 2017/09/11
- bug#28350: enriched.el code execution, Eli Zaretskii, 2017/09/16
bug#28350: enriched.el code execution, Glenn Morris, 2017/09/11