bug-gnu-emacs
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

bug#66390: `man' allows to inject arbitrary shell code


From: Max Nikulin
Subject: bug#66390: `man' allows to inject arbitrary shell code
Date: Wed, 11 Oct 2023 17:56:11 +0700
User-agent: Mozilla Thunderbird

On 10/10/2023 18:56, Richard Stallman wrote:
In general, that is a reasonable policy -- but maybe a serious security problem, which this eesms to be, calls for special treatment.

I would not consider this particular issue as a serious security problem despite if reported as a CVE it may get high score. However, I believe, it should be addressed.

ol-man is not loaded by default.

Enough features for Org mode are convenient in case of trusted files, but close to dangerous when a user walks through a malicious file. There are some issues that requires significant amount of efforts to fix without ruining usability.





reply via email to

[Prev in Thread] Current Thread [Next in Thread]