bug-gnu-emacs
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

bug#47058: 28.0.50; Dired Z: insert-directory: Reading directory: No suc


From: Lars Ingebrigtsen
Subject: bug#47058: 28.0.50; Dired Z: insert-directory: Reading directory: No such file or directory, CrossLine_linux_x86
Date: Tue, 21 Sep 2021 19:10:09 +0200
User-agent: Gnus/5.13 (Gnus v5.13) Emacs/28.0.50 (gnu/linux)

Eli Zaretskii <eliz@gnu.org> writes:

> That's a separate issue.  And I don't see how is it a security issue
> for Emacs, when unpacking an archive manually with 'tar' etc. would
> produce the same results.  If the user wants to overwrite his/her
> sensitive files, we should let them do it, in the same way as other
> utilities do.  But that's MO, and it is a separate concern anyway.

It's an Emacs security issue because we make it so easy to unpack these
tar files.  We should ideally inspect the file first and see whether
it's an adversarial tar file first, and then prompt the user for what to
do.

> I'm okay with having a separate command for unpacking, yes.  We'd need
> to provide a backward-compatibility option if we do that, since 'Z'
> unpacks for some time now.

Separate commands here would be good; yes.

-- 
(domestic pets only, the antidote for overdose, milk.)
   bloggy blog: http://lars.ingebrigtsen.no





reply via email to

[Prev in Thread] Current Thread [Next in Thread]