emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Is CVE-2024-30203 bogus? (Emacs)


From: Max Nikulin
Subject: Re: Is CVE-2024-30203 bogus? (Emacs)
Date: Wed, 10 Apr 2024 22:07:02 +0700
User-agent: Mozilla Thunderbird

On 10/04/2024 21:17, Salvatore Bonaccorso wrote:
On Wed, Apr 10, 2024 at 12:04:06PM +0000, Ihor Radchenko wrote:

Yes, CVE-2024-30203 title is superfluous.
And CVE-2024-30204 title is not accurate - it only applies to
certain attachments with specific (text/x-org) mime type.
[...]
If you think the CVE assignment is not valid, then you might ask for a
REJECT on https://cveform.mitre.org/ .

Do 2 CVE numbers make sense to track fixes in Emacs and Org mode? Various versions of Org mode may be loaded to different versions of Emacs and both parties must have fixes to avoid the issue.




reply via email to

[Prev in Thread] Current Thread [Next in Thread]