emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: emacs-29 3c1693d08b0: Fix Elisp code injection vulnerability in emac


From: Robert Pluim
Subject: Re: emacs-29 3c1693d08b0: Fix Elisp code injection vulnerability in emacsclient-mail.desktop
Date: Wed, 08 Mar 2023 11:44:09 +0100

>>>>> On Wed, 08 Mar 2023 11:39:32 +0100, Ulrich Mueller <ulm@gentoo.org> said:

>>>>> On Wed, 08 Mar 2023, Po Lu wrote:
    >> Please, fix this so it works without bash, or remove it from emacs-29.
    >> Once the pretest comes out, I plan to ask many coworkers to try it out.
    >> Many of their systems use the Korn shell and do not have bash.

    Ulrich> Sorry, but I've installed this on emacs-29 with an explicit ack from
    Ulrich> both Eli and Stefan.

Fair enough, but is there no way to get it to use `sed' instead?

    Ulrich> An alternative solution would be to drop emacsclient-mail.desktop
    Ulrich> altogether, since this desktop file isn't part of any core
    Ulrich> functionality. It could be readded once emacsclient has gained a
    Ulrich> --funcall argument, so that arguments can be passed in a sane way.

No, I think too many people like using that desktop file for us to
yank it like that.

Robert
-- 



reply via email to

[Prev in Thread] Current Thread [Next in Thread]