unofficial mirror of bug-gnu-emacs@gnu.org 
 help / color / mirror / code / Atom feed
* bug#24489: efaq: security risks
@ 2016-09-20 22:48 Glenn Morris
  2016-09-20 22:53 ` Lars Ingebrigtsen
                   ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: Glenn Morris @ 2016-09-20 22:48 UTC (permalink / raw)
  To: 24489

Package: emacs
Severity: minor
Tags: security
Version: 25.1

The (very crufty) Emacs FAQ contains a section:

   "Are there any security risks in Emacs?"

The stuff about movemail and synthetic X events is archaic.

There is no mention of the more current problems:

1) installing a package runs arbitrary code
Better make sure you trust whoever gave you that package (gpg signing)
and how you got it (https), etc.

2) using an Emacs mail client to view HTML mail is a security risk if remote
content is fetched (I think it isn't by default, but this might not
apply to every client)

3) viewing remote HTML content (eg with eww or xwidgets) is likewise a
potential security risk.





^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2022-01-29 16:51 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2016-09-20 22:48 bug#24489: efaq: security risks Glenn Morris
2016-09-20 22:53 ` Lars Ingebrigtsen
2016-09-21 21:26 ` Richard Stallman
2016-09-22 10:56   ` Ted Zlatanov
2016-09-23 20:38     ` Richard Stallman
2016-09-24  2:45       ` Ted Zlatanov
2016-09-25 17:15         ` Richard Stallman
2020-08-12  1:38 ` Stefan Kangas
2022-01-29 16:51   ` Lars Ingebrigtsen

Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/emacs.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).