From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Richard Stallman Newsgroups: gmane.emacs.bugs Subject: bug#19565: Emacs vulnerable to endless-data attack (minor) Date: Sun, 11 Jan 2015 13:33:34 -0500 Message-ID: References: Reply-To: rms@gnu.org NNTP-Posting-Host: plane.gmane.org Content-Type: text/plain; charset=Utf-8 X-Trace: ger.gmane.org 1421001253 4825 80.91.229.3 (11 Jan 2015 18:34:13 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Sun, 11 Jan 2015 18:34:13 +0000 (UTC) Cc: 19565@debbugs.gnu.org To: Kelly Dean Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Sun Jan 11 19:34:08 2015 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1YANKx-0006zD-NV for geb-bug-gnu-emacs@m.gmane.org; Sun, 11 Jan 2015 19:34:07 +0100 Original-Received: from localhost ([::1]:59086 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1YANKx-0002IJ-3C for geb-bug-gnu-emacs@m.gmane.org; Sun, 11 Jan 2015 13:34:07 -0500 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:54987) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1YANKt-0002F6-9r for bug-gnu-emacs@gnu.org; Sun, 11 Jan 2015 13:34:04 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1YANKs-0007Jg-HW for bug-gnu-emacs@gnu.org; Sun, 11 Jan 2015 13:34:03 -0500 Original-Received: from debbugs.gnu.org ([140.186.70.43]:33502) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1YANKs-0007Ja-EE for bug-gnu-emacs@gnu.org; Sun, 11 Jan 2015 13:34:02 -0500 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.80) (envelope-from ) id 1YANKs-0003Mz-6U for bug-gnu-emacs@gnu.org; Sun, 11 Jan 2015 13:34:02 -0500 X-Loop: help-debbugs@gnu.org Resent-From: Richard Stallman Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Sun, 11 Jan 2015 18:34:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 19565 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: Original-Received: via spool by 19565-submit@debbugs.gnu.org id=B19565.142100121712921 (code B ref 19565); Sun, 11 Jan 2015 18:34:02 +0000 Original-Received: (at 19565) by debbugs.gnu.org; 11 Jan 2015 18:33:37 +0000 Original-Received: from localhost ([127.0.0.1]:42868 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1YANKT-0003MK-0A for submit@debbugs.gnu.org; Sun, 11 Jan 2015 13:33:37 -0500 Original-Received: from fencepost.gnu.org ([208.118.235.10]:48598) by debbugs.gnu.org with esmtp (Exim 4.80) (envelope-from ) id 1YANKQ-0003MC-Tc for 19565@debbugs.gnu.org; Sun, 11 Jan 2015 13:33:35 -0500 Original-Received: from rms by fencepost.gnu.org with local (Exim 4.71) (envelope-from ) id 1YANKQ-0006v8-6Y; Sun, 11 Jan 2015 13:33:34 -0500 In-reply-to: (message from Kelly Dean on Sun, 11 Jan 2015 11:12:00 +0000) X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.15 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 3.x X-Received-From: 140.186.70.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.bugs:98228 Archived-At: [[[ To any NSA and FBI agents reading my email: please consider ]]] [[[ whether defending the US Constitution against all enemies, ]]] [[[ foreign or domestic, requires you to follow Snowden's example. ]]] > A few days ago I speculated, but now I confirmed. It's technically considered a vulnerability, but in Emacs's case it's a minor problem; exploiting it would be more a prank than a real attack. That is a relief. -- Dr Richard Stallman President, Free Software Foundation 51 Franklin St Boston MA 02110 USA www.fsf.org www.gnu.org Skype: No way! That's nonfree (freedom-denying) software. Use Ekiga or an ordinary phone call.