emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Reproducers for recent Emacs security issues


From: Max Nikulin
Subject: Re: Reproducers for recent Emacs security issues
Date: Mon, 15 Apr 2024 18:20:12 +0700
User-agent: Mozilla Thunderbird

On 15/04/2024 16:46, Sean Whitton wrote:

emacs -q
M-x gnus-no-server
Gf ~/tmp/mbox-with-the-msgs.mbox
RET

I am not a Gnus user, but this time I have tried it. I have realized that if there is an text/x-org attachment, even a purely innocent one, then it is enough to have the following in the text/plain *body* to trigger an attempt to download a remote file:

#+setupfile: http://localhost:8000/setup-1234567890.org

it happens when I open the message, the attachment remains closed.

I expect that message body should not affect attachment preview.

Emacs-28.2

Attachment: innocent.org
Description: Text Data

Attachment: innocent-x.org
Description: Text Data


reply via email to

[Prev in Thread] Current Thread [Next in Thread]