unofficial mirror of bug-gnu-emacs@gnu.org 
 help / color / mirror / code / Atom feed
* bug#44018: Don't consider play-sound-file to be a 'safe' function
@ 2020-10-15 16:55 Mattias Engdegård
  2020-10-15 17:14 ` Lars Ingebrigtsen
  2020-10-15 17:26 ` Eli Zaretskii
  0 siblings, 2 replies; 22+ messages in thread
From: Mattias Engdegård @ 2020-10-15 16:55 UTC (permalink / raw)
  To: 44018

We should remove play-sound-file from the list of 'safe' functions in unsafep.el.
The risks outweigh the benefits here; this is just basic security engineering.
The attack surface of play-sound-file is considerable.






^ permalink raw reply	[flat|nested] 22+ messages in thread

end of thread, other threads:[~2020-10-31 13:33 UTC | newest]

Thread overview: 22+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2020-10-15 16:55 bug#44018: Don't consider play-sound-file to be a 'safe' function Mattias Engdegård
2020-10-15 17:14 ` Lars Ingebrigtsen
2020-10-15 17:26 ` Eli Zaretskii
2020-10-15 19:01   ` Mattias Engdegård
2020-10-15 19:20     ` Eli Zaretskii
2020-10-16  9:45       ` Mattias Engdegård
2020-10-26 11:51         ` Mattias Engdegård
2020-10-26 15:29           ` Eli Zaretskii
2020-10-26 16:19             ` Mattias Engdegård
2020-10-26 17:09               ` Eli Zaretskii
2020-10-26 18:25                 ` Lars Ingebrigtsen
2020-10-26 16:32           ` Stefan Kangas
2020-10-26 16:51             ` Mattias Engdegård
2020-10-16  5:39   ` Lars Ingebrigtsen
2020-10-16  6:23     ` Eli Zaretskii
2020-10-26 17:05       ` Basil L. Contovounesios
2020-10-26 17:16         ` Eli Zaretskii
2020-10-26 17:38           ` Mattias Engdegård
2020-10-26 18:28             ` Eli Zaretskii
2020-10-26 20:36               ` Mattias Engdegård
2020-10-31  8:06                 ` Eli Zaretskii
2020-10-31 13:33                   ` Mattias Engdegård

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/emacs.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).