[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
bug#66390: `man' allows to inject arbitrary shell code
From: |
Max Nikulin |
Subject: |
bug#66390: `man' allows to inject arbitrary shell code |
Date: |
Wed, 11 Oct 2023 17:56:11 +0700 |
User-agent: |
Mozilla Thunderbird |
On 10/10/2023 18:56, Richard Stallman wrote:
In general, that is a reasonable policy -- but maybe a serious security
problem, which this eesms to be, calls for special treatment.
I would not consider this particular issue as a serious security problem
despite if reported as a CVE it may get high score. However, I believe,
it should be addressed.
ol-man is not loaded by default.
Enough features for Org mode are convenient in case of trusted files,
but close to dangerous when a user walks through a malicious file. There
are some issues that requires significant amount of efforts to fix
without ruining usability.
- bug#66390: `man' allows to inject arbitrary shell code, (continued)
- bug#66390: `man' allows to inject arbitrary shell code, lux, 2023/10/10
- bug#66390: `man' allows to inject arbitrary shell code, Max Nikulin, 2023/10/11
- bug#66390: `man' allows to inject arbitrary shell code, Stefan Kangas, 2023/10/20
- bug#66390: `man' allows to inject arbitrary shell code, Eli Zaretskii, 2023/10/21
- bug#66390: `man' allows to inject arbitrary shell code, Andreas Schwab, 2023/10/21
- bug#66390: `man' allows to inject arbitrary shell code, Eli Zaretskii, 2023/10/21
- bug#66390: `man' allows to inject arbitrary shell code, Stefan Kangas, 2023/10/21
- bug#66390: `man' allows to inject arbitrary shell code, Richard Stallman, 2023/10/08
- bug#66390: `man' allows to inject arbitrary shell code, Eli Zaretskii, 2023/10/09
- bug#66390: `man' allows to inject arbitrary shell code, Richard Stallman, 2023/10/10
- bug#66390: `man' allows to inject arbitrary shell code,
Max Nikulin <=
- bug#66390: `man' allows to inject arbitrary shell code, Maxim Nikulin, 2023/10/08
- bug#66390: `man' allows to inject arbitrary shell code, Eli Zaretskii, 2023/10/08