emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: release bugs [was Re: Processed: enriched.el code execution]


From: John Wiegley
Subject: Re: release bugs [was Re: Processed: enriched.el code execution]
Date: Thu, 07 Sep 2017 14:11:56 +0100
User-agent: Gnus/5.130016 (Ma Gnus v0.16) Emacs/25.2.50 (darwin)

>>>>> "PE" == Paul Eggert <address@hidden> writes:

PE> This particular bug involved remote code execution by visiting an email
PE> attachment. Any security hole this serious should be blocking. It doesn't
PE> matter that the bug has been around for a while, as the bug is known now
PE> and is likely to be exploited by anyone who cares to attack Emacs users.
PE> I'm surprised that there was controversy about this case, as the bug
PE> really should be fixed as soon as we reasonably can, or in any event
PE> before the next release.

It does seem that this issue should be easy enough to fix that we can delay
until it's included.

-- 
John Wiegley                  GPG fingerprint = 4710 CF98 AF9B 327B B80F
http://newartisans.com                          60E1 46C4 BD1A 7AC1 4BA2



reply via email to

[Prev in Thread] Current Thread [Next in Thread]